face-unlock-bin: new package

This commit is contained in:
Felitendo committed 2026-09-28 10:52:04 +02:00
1 parent 927c0a486b
commit 8e503c37f1
5 files changed
+168 -1

No files matched your search

+3 -1
View File
@@ -48,6 +48,7 @@ source in the `PKGBUILD` (and drop the `-bin` suffix), or don't package it.
| `concat-bin` | [jub0t/Concat](https://github.com/jub0t/Concat) — prebuilt release of `concat` | `.deb` | [concat-bin](https://aur.archlinux.org/packages/concat-bin) | | `concat-bin` | [jub0t/Concat](https://github.com/jub0t/Concat) — prebuilt release of `concat` | `.deb` | [concat-bin](https://aur.archlinux.org/packages/concat-bin) |
| `concat-git` | [jub0t/Concat](https://github.com/jub0t/Concat) — `main` branch of `concat` | *built from source* | [concat-git](https://aur.archlinux.org/packages/concat-git) | | `concat-git` | [jub0t/Concat](https://github.com/jub0t/Concat) — `main` branch of `concat` | *built from source* | [concat-git](https://aur.archlinux.org/packages/concat-git) |
| `face-unlock` | [LoonixTools/face-unlock](https://github.com/LoonixTools/face-unlock): Face ID for Linux, for the lock screen, sudo and admin prompts on Plasma, GNOME, Hyprland and Niri, with a photo check (C++/Qt6, OpenCV). Called `plasma-face-unlock` before 2.0.0 | *built from source* | [face-unlock](https://aur.archlinux.org/packages/face-unlock) | | `face-unlock` | [LoonixTools/face-unlock](https://github.com/LoonixTools/face-unlock): Face ID for Linux, for the lock screen, sudo and admin prompts on Plasma, GNOME, Hyprland and Niri, with a photo check (C++/Qt6, OpenCV). Called `plasma-face-unlock` before 2.0.0 | *built from source* | [face-unlock](https://aur.archlinux.org/packages/face-unlock) |
| `face-unlock-bin` | [LoonixTools/face-unlock](https://github.com/LoonixTools/face-unlock): prebuilt release of `face-unlock`, with OpenCV linked in | tarball (built on Arch) | [face-unlock-bin](https://aur.archlinux.org/packages/face-unlock-bin) |
| `faugus-launcher-bin` | [Faugus/faugus-launcher](https://github.com/Faugus/faugus-launcher) — launcher for Windows games via UMU-Launcher | `.deb` (`all`) | [faugus-launcher-bin](https://aur.archlinux.org/packages/faugus-launcher-bin) | | `faugus-launcher-bin` | [Faugus/faugus-launcher](https://github.com/Faugus/faugus-launcher) — launcher for Windows games via UMU-Launcher | `.deb` (`all`) | [faugus-launcher-bin](https://aur.archlinux.org/packages/faugus-launcher-bin) |
| `fluxer-bin` | [fluxer.app](https://fluxer.app) — Fluxer desktop client (Electron) | tarball | [fluxer-bin](https://aur.archlinux.org/packages/fluxer-bin) | | `fluxer-bin` | [fluxer.app](https://fluxer.app) — Fluxer desktop client (Electron) | tarball | [fluxer-bin](https://aur.archlinux.org/packages/fluxer-bin) |
| `kitty-tune-bin` | [alan7383/KittyTuneDesktop](https://github.com/alan7383/KittyTuneDesktop) — SoundCloud and YouTube music player (Kotlin/Compose Multiplatform) | `.deb` | [kitty-tune-bin](https://aur.archlinux.org/packages/kitty-tune-bin) | | `kitty-tune-bin` | [alan7383/KittyTuneDesktop](https://github.com/alan7383/KittyTuneDesktop) — SoundCloud and YouTube music player (Kotlin/Compose Multiplatform) | `.deb` | [kitty-tune-bin](https://aur.archlinux.org/packages/kitty-tune-bin) |
@@ -117,7 +118,8 @@ Then create a directory named after the AUR package containing:
- `AUR_PUBLISH` — optional; set to `false` to keep a package out of the AUR - `AUR_PUBLISH` — optional; set to `false` to keep a package out of the AUR
while it is still being prepared. Everything else still runs, so the while it is still being prepared. Everything else still runs, so the
`PKGBUILD` is kept current and test-built; only the publishing waits. `PKGBUILD` is kept current and test-built; only the publishing waits.
Flip it to `true` to go live (`moondeckbuddy-bin`). Flip it to `true` to go live (`moondeckbuddy-bin`). `face-unlock-bin` sets it
itself: it goes live with the first release that has its tarball.
Other local source files in the directory (`.desktop` files, patches, …) are Other local source files in the directory (`.desktop` files, patches, …) are
pushed to the AUR alongside `PKGBUILD` and `.SRCINFO`. pushed to the AUR alongside `PKGBUILD` and `.SRCINFO`.
+44
View File
@@ -0,0 +1,44 @@
pkgbase = face-unlock-bin
pkgdesc = Face ID for Linux: the lock screen, sudo and admin prompts by face, on Plasma, GNOME, Hyprland and Niri (upstream binary)
pkgver = 0
pkgrel = 1
url = https://github.com/LoonixTools/face-unlock
install = face-unlock-bin.install
arch = x86_64
license = GPL-3.0-or-later
license = MIT
license = Apache-2.0
license = BSD-3-Clause
license = IJG
license = Zlib
license = libpng-2.0
depends = bash
depends = coreutils
depends = gawk
depends = grep
depends = sed
depends = gettext
depends = systemd
depends = systemd-libs
depends = pam
depends = polkit
depends = qt6-base
depends = qt6-declarative
depends = qt6-wayland
depends = wayland
depends = layer-shell-qt
depends = ki18n
depends = glibc
depends = libgcc
depends = libstdc++
depends = hicolor-icon-theme
optdepends = hyprpolkitagent: password windows on Hyprland and Niri
provides = face-unlock
conflicts = face-unlock
conflicts = plasma-face-unlock
noextract = face-unlock-0-arch-x86_64.tar.zst
options = !debug
source = face-unlock-0-arch-x86_64.tar.zst::https://github.com/LoonixTools/face-unlock/releases/download/v0/face-unlock-0-arch-x86_64.tar.zst
sha256sums = SKIP
pkgname = face-unlock-bin
+38
View File
@@ -0,0 +1,38 @@
# Maintainer: Felitendo
# This PKGBUILD is updated automatically:
# https://github.com/Felitendo/PKGBUILDS
pkgname=face-unlock-bin
pkgver=0
pkgrel=1
pkgdesc="Face ID for Linux: the lock screen, sudo and admin prompts by face, on Plasma, GNOME, Hyprland and Niri (upstream binary)"
arch=('x86_64')
url="https://github.com/LoonixTools/face-unlock"
# The program is GPL, the two face networks are MIT (YuNet) and Apache-2.0
# (SFace). The daemon has OpenCV (Apache-2.0) linked in, with its copies of
# protobuf, libjpeg-turbo, libpng and zlib. All texts are in the package.
license=('GPL-3.0-or-later' 'MIT' 'Apache-2.0' 'BSD-3-Clause' 'IJG' 'Zlib' 'libpng-2.0')
# What the binaries load, plus what the face-unlock command runs. No opencv:
# it is linked in.
depends=('bash' 'coreutils' 'gawk' 'grep' 'sed' 'gettext' 'systemd' 'systemd-libs' 'pam' 'polkit'
'qt6-base' 'qt6-declarative' 'qt6-wayland' 'wayland' 'layer-shell-qt' 'ki18n'
'glibc' 'libgcc' 'libstdc++' 'hicolor-icon-theme')
optdepends=('hyprpolkitagent: password windows on Hyprland and Niri')
provides=('face-unlock')
conflicts=('face-unlock' 'plasma-face-unlock')
install="${pkgname}.install"
options=('!debug')
# Upstream's release workflow builds this tarball on Arch: the make install
# tree of face-unlock, in one folder. The agent uses Qt's private API, so it
# fits the Qt that Arch had at the release.
_tarball="face-unlock-${pkgver}-arch-${CARCH}.tar.zst"
source=("${_tarball}::${url}/releases/download/v${pkgver}/${_tarball}")
noextract=("${_tarball}")
sha256sums=('SKIP')
package() {
# extracted here and not by makepkg, so the files keep the root owner
# the tarball gives them
bsdtar -xpf "$srcdir/${_tarball}" -C "$pkgdir" --strip-components 1
mv "$pkgdir/usr/share/licenses/face-unlock" "$pkgdir/usr/share/licenses/$pkgname"
}
+34
View File
@@ -0,0 +1,34 @@
post_install() {
# Faces, settings and PAM lines of plasma-face-unlock, the old name.
face-unlock --root migrate >/dev/null 2>&1 || true
cat <<'MSG'
face-unlock is installed. Run it as your own user, not with sudo:
face-unlock interactive menu
face-unlock enable set up your face and turn it on
It asks for your password when it needs to. sudo and admin prompts stay
with the password until you switch them on under Settings.
MSG
}
post_upgrade() {
face-unlock --root migrate >/dev/null 2>&1 || true
}
pre_remove() {
cat <<'MSG'
Before removing this package, run
face-unlock disable
as each user that turned it on. That takes face unlock back out of sudo,
polkit and the lock screens. (Removing it without that is safe too: the PAM
line is written so that a missing module is skipped.)
MSG
systemctl disable --now face-unlockd.socket face-unlockd.service >/dev/null 2>&1 || true
}
+49
View File
@@ -0,0 +1,49 @@
# face-unlock-bin - the Arch build of face-unlock
# (https://github.com/LoonixTools/face-unlock), made by upstream's release
# workflow: the same program as the face-unlock package, with OpenCV linked in
# statically, so an OpenCV update on Arch does not break it.
#
# Not every release has the tarball (2.0.0 and older do not), so the newest
# release that has it is tracked, not /releases/latest. The checksum is the
# digest GitHub keeps for every release asset.
UPSTREAM_REPO="LoonixTools/face-unlock"
# newest published release with an Arch tarball, as its tag
latest_tag() {
gh api "repos/$UPSTREAM_REPO/releases?per_page=30" \
--jq '[.[] | select((.draft or .prerelease) | not)
| select(any(.assets[]; .name | endswith("-arch-x86_64.tar.zst")))]
| first | .tag_name // empty'
}
# Kept off the AUR until a release has the tarball: until then the PKGBUILD
# has nothing to point at. The run that finds the first one updates the
# PKGBUILD and test-builds it before anything is pushed.
AUR_PUBLISH=false
if [[ -n "$(latest_tag)" ]]; then
AUR_PUBLISH=true
fi
latest_version() {
local tag
tag="$(latest_tag)"
[[ -n "$tag" ]] || return 75
echo "${tag#v}"
}
# refresh_checksums <version> <pkgbuild-path>
refresh_checksums() {
local ver="$1" pkgbuild="$2"
local name="face-unlock-$ver-arch-x86_64.tar.zst" sha
sha="$(gh api "repos/$UPSTREAM_REPO/releases/tags/v$ver" \
--jq ".assets[] | select(.name == \"$name\") | .digest // empty" \
| sed -n 's/^sha256://p')"
if [[ ! "$sha" =~ ^[0-9a-f]{64}$ ]]; then
sha="$(curl -sfL "https://github.com/$UPSTREAM_REPO/releases/download/v$ver/$name" \
| sha256sum | cut -d' ' -f1)"
fi
sed -i "s|^sha256sums=.*|sha256sums=('$sha')|" "$pkgbuild"
}