commit f671acc93b2c0fe8e12a1617a653d38bc7d056a8 Author: Felitendo Date: Tue Sep 22 19:35:32 2026 +0200 feat: add plasma-face-unlock diff --git a/.gitattributes b/.gitattributes new file mode 100644 index 0000000..dfe0770 --- /dev/null +++ b/.gitattributes @@ -0,0 +1,2 @@ +# Auto detect text files and perform LF normalization +* text=auto diff --git a/.github/FUNDING.yml b/.github/FUNDING.yml new file mode 100644 index 0000000..de63b10 --- /dev/null +++ b/.github/FUNDING.yml @@ -0,0 +1,15 @@ +# These are supported funding model platforms + +github: Felitendo +patreon: # Replace with a single Patreon username +open_collective: # Replace with a single Open Collective username +ko_fi: # Replace with a single Ko-fi username +tidelift: # Replace with a single Tidelift platform-name/package-name e.g., npm/babel +community_bridge: # Replace with a single Community Bridge project-name e.g., cloud-foundry +liberapay: # Replace with a single Liberapay username +issuehunt: # Replace with a single IssueHunt username +lfx_crowdfunding: # Replace with a single LFX Crowdfunding project-name e.g., cloud-foundry +polar: # Replace with a single Polar username +buy_me_a_coffee: felitendo +thanks_dev: # Replace with a single thanks.dev username +custom: # Replace with up to 4 custom sponsorship URLs e.g., ['link1', 'link2'] diff --git a/.github/workflows/check.yml b/.github/workflows/check.yml new file mode 100644 index 0000000..0819adc --- /dev/null +++ b/.github/workflows/check.yml @@ -0,0 +1,32 @@ +name: check + +on: + push: + branches: [main] + pull_request: + workflow_dispatch: + +jobs: + check: + name: build, tests and shellcheck + runs-on: ubuntu-latest + # Arch has every Plasma 6 and Qt 6 development package this needs, and the + # newest OpenCV, which is the one that moved things around. + container: archlinux:latest + steps: + - name: Install the build tools + run: | + pacman -Syu --noconfirm --needed git base-devel cmake pkgconf \ + qt6-base qt6-declarative layer-shell-qt kidletime ki18n \ + opencv pam systemd-libs gettext scdoc shellcheck desktop-file-utils + + - uses: actions/checkout@v7 + + - run: make check + + # The liveness cues against synthetic heads and photos, the face store, + # and the PAM file editing (with real PAM for the last part). + - run: make test + + - name: Build the catalogs and the man page + run: make build diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml new file mode 100644 index 0000000..5c526cd --- /dev/null +++ b/.github/workflows/release.yml @@ -0,0 +1,254 @@ +name: release + +on: + push: + tags: ['v*'] + workflow_dispatch: + inputs: + dry_run: + description: >- + Build the repositories with a throwaway key and install from them, + without publishing anything. + type: boolean + default: false + +permissions: + contents: write + +jobs: + deb: + name: Debian package + runs-on: ubuntu-latest + # Plasma 6 arrived in Debian with trixie. + container: debian:trixie + steps: + - name: Install the build tools + run: | + apt-get update -qq + apt-get install -y --no-install-recommends \ + ca-certificates curl git make cmake g++ pkg-config gettext scdoc dpkg-dev \ + qt6-base-dev qt6-base-private-dev qt6-declarative-dev \ + qt6-wayland-dev qt6-wayland-dev-tools qt6-wayland-private-dev \ + liblayershellqtinterface-dev libkf6idletime-dev libkf6i18n-dev \ + libopencv-dev libpam0g-dev libsystemd-dev + + - uses: actions/checkout@v7 + + - name: Check the tag against the Makefile + run: packaging/check-version.sh "${{ github.ref_name }}" + + - run: packaging/build-deb.sh + + - name: Look inside what was built + run: | + dpkg-deb --info dist/*.deb + dpkg-deb --contents dist/*.deb + + - uses: actions/upload-artifact@v7 + with: + name: deb + path: dist/*.deb + if-no-files-found: error + + rpm: + name: RPM package + runs-on: ubuntu-latest + container: fedora:latest + steps: + - name: Install the build tools + run: | + dnf install -y --setopt=install_weak_deps=False \ + git make cmake gcc-c++ gettext scdoc tar curl rpm-build rpm-sign systemd-rpm-macros \ + 'pkgconfig(systemd)' 'pkgconfig(libsystemd)' pam-devel opencv-devel \ + qt6-qtbase-devel qt6-qtbase-private-devel qt6-qtdeclarative-devel qt6-qtwayland-devel \ + layer-shell-qt-devel kf6-kidletime-devel kf6-ki18n-devel + + - uses: actions/checkout@v7 + + - name: Check the tag against the Makefile + run: packaging/check-version.sh "${{ github.ref_name }}" + + - run: packaging/build-rpm.sh + + - name: Sign the package + env: + GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }} + DRY_RUN: ${{ inputs.dry_run }} + run: | + if [ "$DRY_RUN" = "true" ]; then + gpg --batch --passphrase '' --quick-generate-key \ + 'dry run ' rsa2048 sign never + elif [ -n "${GPG_PRIVATE_KEY:-}" ]; then + printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import + else + echo "No GPG_PRIVATE_KEY secret; leaving the package unsigned." + exit 0 + fi + keyid="$(gpg --list-secret-keys --with-colons | awk -F: '/^sec:/ { print $5; exit }')" + rpmsign --define "_gpg_name $keyid" --addsign dist/*.rpm + gpg --armor --export "$keyid" > dist/rpm-signer.asc + rpm --import dist/rpm-signer.asc + rpm --checksig dist/*.rpm + + - name: Look inside what was built + run: | + rpm -qip dist/plasma-face-unlock-[0-9]*.rpm + rpm -qlp dist/plasma-face-unlock-[0-9]*.rpm + + - uses: actions/upload-artifact@v7 + with: + name: rpm + path: | + dist/*.rpm + dist/rpm-signer.asc + if-no-files-found: error + + publish: + name: Release and repositories + needs: [deb, rpm] + if: startsWith(github.ref, 'refs/tags/v') || inputs.dry_run + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v7 + + - uses: actions/download-artifact@v8 + with: + path: incoming + merge-multiple: true + + - name: Attach the packages to the release + if: ${{ !inputs.dry_run }} + env: + GH_TOKEN: ${{ github.token }} + run: | + gh release create "${{ github.ref_name }}" \ + --title "${{ github.ref_name }}" \ + --generate-notes \ + incoming/*.deb incoming/*.rpm \ + || gh release upload "${{ github.ref_name }}" \ + incoming/*.deb incoming/*.rpm --clobber + + - name: Install the repository tools + run: | + sudo apt-get update -qq + sudo apt-get install -y --no-install-recommends \ + dpkg-dev apt-utils createrepo-c + + - name: Get a signing key + id: key + env: + GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }} + DRY_RUN: ${{ inputs.dry_run }} + run: | + if [ "$DRY_RUN" = "true" ]; then + gpg --batch --passphrase '' --quick-generate-key \ + 'dry run ' rsa2048 sign never + elif [ -n "${GPG_PRIVATE_KEY:-}" ]; then + printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import + else + echo "present=no" >> "$GITHUB_OUTPUT" + echo "::warning::No GPG_PRIVATE_KEY secret, so the apt and dnf repositories were not updated. The packages are on the release." + exit 0 + fi + echo "present=yes" >> "$GITHUB_OUTPUT" + + - name: Check out the published repositories + if: steps.key.outputs.present == 'yes' && !inputs.dry_run + uses: actions/checkout@v7 + with: + ref: gh-pages + path: pages + continue-on-error: true + + - name: Update the repositories + if: steps.key.outputs.present == 'yes' + run: | + if [ ! -d pages/.git ]; then + rm -rf pages && mkdir pages + git -C pages init -q -b gh-pages + git -C pages remote add origin "https://github.com/${{ github.repository }}.git" + fi + rm -f incoming/rpm-signer.asc + packaging/publish-repos.sh pages incoming + + - name: Check that what was written can be verified + if: steps.key.outputs.present == 'yes' + run: | + gpg --verify pages/deb/InRelease + gpg --verify pages/deb/Release.gpg pages/deb/Release + gpg --verify pages/rpm/repodata/repomd.xml.asc pages/rpm/repodata/repomd.xml + + - uses: actions/upload-artifact@v7 + if: inputs.dry_run + with: + name: pages + path: pages + include-hidden-files: true + + - name: Push them + if: steps.key.outputs.present == 'yes' && !inputs.dry_run + env: + GH_TOKEN: ${{ github.token }} + run: | + cd pages + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git add -A + git diff --quiet --cached && { echo "nothing changed"; exit 0; } + git commit -q -m "Publish ${{ github.ref_name }}" + git push "https://x-access-token:${GH_TOKEN}@github.com/${{ github.repository }}.git" HEAD:gh-pages + + verify-apt: + name: Install from the APT repository + needs: publish + if: inputs.dry_run + runs-on: ubuntu-latest + container: debian:trixie + steps: + - uses: actions/download-artifact@v8 + with: + name: pages + path: pages + - name: Install from the repository that was just built + run: | + apt-get update -qq && apt-get install -y --no-install-recommends gpg + install -d -m 0755 /etc/apt/keyrings + gpg --dearmor -o /etc/apt/keyrings/plasma-face-unlock.gpg < pages/KEY.gpg + echo "deb [signed-by=/etc/apt/keyrings/plasma-face-unlock.gpg] file://$PWD/pages/deb ./" \ + > /etc/apt/sources.list.d/plasma-face-unlock.list + apt-get update + apt-get install -y plasma-face-unlock + useradd -m tester + runuser -u tester -- plasma-face-unlock --version + + verify-dnf: + name: Install from the RPM repository + needs: publish + if: inputs.dry_run + runs-on: ubuntu-latest + container: fedora:latest + steps: + - uses: actions/download-artifact@v8 + with: + name: pages + path: pages + - uses: actions/download-artifact@v8 + with: + name: rpm + path: signer + - name: Install from the repository that was just built + run: | + rpm --import pages/KEY.gpg + rpm --import signer/rpm-signer.asc + cat > /etc/yum.repos.d/plasma-face-unlock.repo <` or + `Camera=file: