feat: add plasma-face-unlock

This commit is contained in:
Felitendo committed 2026-09-22 19:39:04 +02:00
commit f671acc93b
105 files changed
+13862

No files matched your search

@@ -0,0 +1,13 @@
[Desktop Entry]
Type=Application
Name=Plasma Face Unlock
Name[de]=Plasma-Gesichtsentsperrung
Comment=Unlocks the lock screen, sudo and admin prompts with your face
Comment[de]=Entsperrt Sperrbildschirm, sudo und Admin-Abfragen mit deinem Gesicht
Exec=@LIBEXECDIR@/plasma-face-unlock-agent
Icon=plasma-face-unlock
NoDisplay=true
OnlyShowIn=KDE;
# KWin only lets a program show above the lock screen when its desktop file
# asks for it by name. This is that file.
X-KDE-Wayland-Interfaces=kde_lockscreen_overlay_v1
+22
View File
@@ -0,0 +1,22 @@
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 512 512" width="512" height="512">
<defs>
<linearGradient id="disc" x1="0" y1="0" x2="1" y2="1"><stop offset="0" stop-color="#5fd0ff"/><stop offset="1" stop-color="#0c62a0"/></linearGradient>
<radialGradient id="glow" cx=".35" cy=".25" r=".7"><stop offset="0" stop-color="#ffffff" stop-opacity=".28"/><stop offset="1" stop-color="#ffffff" stop-opacity="0"/></radialGradient>
<filter id="soft" x="-20%" y="-20%" width="140%" height="150%"><feDropShadow dx="0" dy="10" stdDeviation="12" flood-color="#04213a" flood-opacity=".35"/></filter>
</defs>
<g filter="url(#soft)">
<circle cx="256" cy="246" r="200" fill="url(#disc)"/>
<circle cx="256" cy="246" r="200" fill="url(#glow)"/>
</g>
<!-- the face from the bubble: four brackets, two eyes, a nose, a smile -->
<g transform="translate(136 126) scale(2.4)" fill="none" stroke="#ffffff" stroke-width="5.8" stroke-linecap="round" stroke-linejoin="round">
<path d="M6 30 V19 Q6 6 19 6 H30"/>
<path d="M70 6 H81 Q94 6 94 19 V30"/>
<path d="M94 70 V81 Q94 94 81 94 H70"/>
<path d="M30 94 H19 Q6 94 6 81 V70"/>
<path d="M34 36 V45"/>
<path d="M66 36 V45"/>
<path d="M50 37 V56 Q50 61 45 61"/>
<path d="M35 70 Q50 81 65 70"/>
</g>
</svg>

After

Width:  |  Height:  |  Size: 1.3 KiB

@@ -0,0 +1,24 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE policyconfig PUBLIC
"-//freedesktop//DTD PolicyKit Policy Configuration 1.0//EN"
"http://www.freedesktop.org/standards/PolicyKit/1/policyconfig.dtd">
<policyconfig>
<vendor>LoonixTools</vendor>
<vendor_url>https://github.com/LoonixTools/plasma-face-unlock</vendor_url>
<icon_name>plasma-face-unlock</icon_name>
<!-- A face is a way in, so adding, changing or deleting one takes the
password, the way a phone asks for its code before it sets up a face.
The daemon refuses to let a face answer this particular question. -->
<action id="io.github.loonixtools.plasma-face-unlock.manage">
<description>Change the faces that can unlock your account</description>
<description xml:lang="de">Gesichter ändern, die dein Konto entsperren können</description>
<message>Authentication is required to change the faces that can unlock your account.</message>
<message xml:lang="de">Zum Ändern der Gesichter, die dein Konto entsperren können, ist eine Legitimierung erforderlich.</message>
<defaults>
<allow_any>no</allow_any>
<allow_inactive>no</allow_inactive>
<allow_active>auth_self_keep</allow_active>
</defaults>
</action>
</policyconfig>
Binary file not shown.

After

Width:  |  Height:  |  Size: 79 KiB

@@ -0,0 +1,17 @@
[Unit]
Description=Face unlock for KDE Plasma (lock screen and bubble)
Documentation=man:plasma-face-unlock(1)
PartOf=graphical-session.target
After=graphical-session.target
# Plasma on Wayland. The bubble is a layer-shell surface, and there is no such
# thing on X11.
ConditionEnvironment=WAYLAND_DISPLAY
[Service]
ExecStart=@LIBEXECDIR@/plasma-face-unlock-agent
Restart=on-failure
RestartSec=3
Slice=session.slice
[Install]
WantedBy=graphical-session.target
+40
View File
@@ -0,0 +1,40 @@
[Unit]
Description=Face unlock for KDE Plasma
Documentation=man:plasma-face-unlock(1)
Requires=plasma-face-unlockd.socket
After=plasma-face-unlockd.socket
[Service]
Type=simple
# Started by the socket, and gone again after a minute with nothing to do.
ExecStart=@LIBEXECDIR@/plasma-face-unlockd
StateDirectory=plasma-face-unlock
StateDirectoryMode=0700
UMask=0077
# It reads a camera, runs two small networks and writes one directory. That is
# all it is allowed to do.
CapabilityBoundingSet=CAP_DAC_READ_SEARCH
# The one capability: to reach a user's agent socket through their 0700
# runtime directory, to tell the bubble about a sudo scan.
NoNewPrivileges=yes
ProtectSystem=strict
ProtectHome=read-only
PrivateTmp=yes
PrivateNetwork=yes
RestrictAddressFamilies=AF_UNIX
DevicePolicy=closed
DeviceAllow=char-video4linux rw
ProtectKernelTunables=yes
ProtectKernelModules=yes
ProtectKernelLogs=yes
ProtectControlGroups=yes
ProtectClock=yes
ProtectHostname=yes
RestrictNamespaces=yes
RestrictRealtime=yes
RestrictSUIDSGID=yes
LockPersonality=yes
SystemCallArchitectures=native
SystemCallFilter=@system-service
SystemCallErrorNumber=EPERM
+14
View File
@@ -0,0 +1,14 @@
[Unit]
Description=Face unlock for KDE Plasma (socket)
Documentation=man:plasma-face-unlock(1)
[Socket]
# Everybody may connect. Who may ask for what is decided per request, by the
# daemon, from the credentials the kernel reports for the other end.
ListenStream=/run/plasma-face-unlock/socket
SocketMode=0666
DirectoryMode=0755
RemoveOnStop=yes
[Install]
WantedBy=sockets.target