From b24703eeea766432d0192bc6accc0b69f1620bc8 Mon Sep 17 00:00:00 2001 From: Felitendo Date: Sat, 26 Sep 2026 20:03:16 +0200 Subject: [PATCH] fix: switch the daemon on after moving over from plasma-face-unlock --- src/lib/migrate.sh | 10 +++++++++- tests/test_pam.sh | 12 +++++++++--- 2 files changed, 18 insertions(+), 4 deletions(-) diff --git a/src/lib/migrate.sh b/src/lib/migrate.sh index 50d03ca..10d3a7f 100644 --- a/src/lib/migrate.sh +++ b/src/lib/migrate.sh @@ -48,7 +48,7 @@ _fu_pam_drop_old() { # The system settings, the faces, sudo and admin prompts and the daemon's # socket, as plasma-face-unlock left them. fu_migrate_system() { - local service link + local service link used=0 if [[ -d $FU_OLD_SYSDIR ]]; then if [[ -f $FU_OLD_SYSDIR/config && ! -e $FU_SYSCONFIG ]]; then @@ -63,6 +63,7 @@ fu_migrate_system() { install -d -m 0700 "$FU_STATEDIR" || return 1 rm -rf -- "$FU_STATEDIR/users" mv -- "$FU_OLD_STATEDIR/users" "$FU_STATEDIR/users" || return 1 + used=1 fi rm -rf -- "$FU_OLD_STATEDIR" fi @@ -70,12 +71,19 @@ fu_migrate_system() { for service in "${FU_PAM_SERVICES[@]}"; do _fu_pam_has_old "$service" || continue _fu_pam_drop_old "$service" && fu_pam_enable "$service" + used=1 done link="$(_fu_old_socket_link)" if [[ -L $link ]]; then systemctl disable --now "${FU_OLD_NAME}d.socket" > /dev/null 2>&1 || true rm -f -- "$link" + used=1 + fi + + # The old package switches its socket off when it is removed, mostly before + # this runs. So its faces and PAM lines count as the sign that it was used. + if (( used )); then systemctl enable --now "$FU_UNIT_SOCKET" > /dev/null 2>&1 || true fi return 0 diff --git a/tests/test_pam.sh b/tests/test_pam.sh index 2e9e689..9241315 100644 --- a/tests/test_pam.sh +++ b/tests/test_pam.sh @@ -166,6 +166,10 @@ FU_SYSCONFIG="$tmp/new-etc/config" FU_SYSTEMD_ETC="$tmp/systemd" old_module=/usr/lib/security/pam_plasma_face_unlock.so +# systemctl is only written down. +# shellcheck disable=SC2329 # called by fu_migrate_system and fu_migrate_user +systemctl() { printf '%s\n' "$*" >> "$tmp/systemctl"; } + # What plasma-face-unlock wrote is what this writes, under the old name. make_old() { sed -i -e "s|^$FU_PAM_MARK\$|$FU_OLD_PAM_MARK|" -e "s|$FU_PAM_WRAPPER_MARK|$FU_OLD_PAM_WRAPPER_MARK|" \ @@ -199,19 +203,21 @@ mkdir -p "$FU_OLD_SYSDIR" "$FU_OLD_STATEDIR/users" echo 'Liveness=heavy' > "$FU_OLD_SYSDIR/config" echo '{}' > "$FU_OLD_STATEDIR/users/1000.json" check "old settings and faces are found" 'fu_migrate_pending' +: > "$tmp/systemctl" fu_migrate_system check "the system settings moved" '[[ $(cat "$FU_SYSCONFIG") == Liveness=heavy && ! -e $FU_OLD_SYSDIR ]]' check "the faces moved" '[[ $(cat "$FU_STATEDIR/users/1000.json") == "{}" && ! -e $FU_OLD_STATEDIR ]]' +check "the socket is on, although the old package switched its own off" 'grep -qx "enable --now face-unlockd.socket" "$tmp/systemctl"' mkdir -p "$FU_OLD_STATEDIR/users" echo old > "$FU_OLD_STATEDIR/users/1000.json" +: > "$tmp/systemctl" fu_migrate_system check "faces set up under the new name win" '[[ $(cat "$FU_STATEDIR/users/1000.json") == "{}" && ! -e $FU_OLD_STATEDIR ]]' +check "and the socket is left as it is" '[[ ! -s $tmp/systemctl ]]' check "nothing is left over at the end" '! fu_migrate_pending' -# This user's side, with systemctl only written down. -# shellcheck disable=SC2329 # called by fu_migrate_user -systemctl() { printf '%s\n' "$*" >> "$tmp/systemctl"; } +# This user's side. FU_XDG_CONFIG="$tmp/home-config" FU_CONFDIR="$FU_XDG_CONFIG/face-unlock" mkdir -p "$FU_XDG_CONFIG/plasma-face-unlock" "$FU_XDG_CONFIG/systemd/user/graphical-session.target.wants"