feat: add plasma-face-unlock
This commit is contained in:
commit
f671acc93b
105 files changed
+13862
No files matched your search
@@ -0,0 +1,17 @@
|
||||
[Unit]
|
||||
Description=Face unlock for KDE Plasma (lock screen and bubble)
|
||||
Documentation=man:plasma-face-unlock(1)
|
||||
PartOf=graphical-session.target
|
||||
After=graphical-session.target
|
||||
# Plasma on Wayland. The bubble is a layer-shell surface, and there is no such
|
||||
# thing on X11.
|
||||
ConditionEnvironment=WAYLAND_DISPLAY
|
||||
|
||||
[Service]
|
||||
ExecStart=@LIBEXECDIR@/plasma-face-unlock-agent
|
||||
Restart=on-failure
|
||||
RestartSec=3
|
||||
Slice=session.slice
|
||||
|
||||
[Install]
|
||||
WantedBy=graphical-session.target
|
||||
@@ -0,0 +1,40 @@
|
||||
[Unit]
|
||||
Description=Face unlock for KDE Plasma
|
||||
Documentation=man:plasma-face-unlock(1)
|
||||
Requires=plasma-face-unlockd.socket
|
||||
After=plasma-face-unlockd.socket
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
# Started by the socket, and gone again after a minute with nothing to do.
|
||||
ExecStart=@LIBEXECDIR@/plasma-face-unlockd
|
||||
StateDirectory=plasma-face-unlock
|
||||
StateDirectoryMode=0700
|
||||
UMask=0077
|
||||
|
||||
# It reads a camera, runs two small networks and writes one directory. That is
|
||||
# all it is allowed to do.
|
||||
CapabilityBoundingSet=CAP_DAC_READ_SEARCH
|
||||
# The one capability: to reach a user's agent socket through their 0700
|
||||
# runtime directory, to tell the bubble about a sudo scan.
|
||||
NoNewPrivileges=yes
|
||||
ProtectSystem=strict
|
||||
ProtectHome=read-only
|
||||
PrivateTmp=yes
|
||||
PrivateNetwork=yes
|
||||
RestrictAddressFamilies=AF_UNIX
|
||||
DevicePolicy=closed
|
||||
DeviceAllow=char-video4linux rw
|
||||
ProtectKernelTunables=yes
|
||||
ProtectKernelModules=yes
|
||||
ProtectKernelLogs=yes
|
||||
ProtectControlGroups=yes
|
||||
ProtectClock=yes
|
||||
ProtectHostname=yes
|
||||
RestrictNamespaces=yes
|
||||
RestrictRealtime=yes
|
||||
RestrictSUIDSGID=yes
|
||||
LockPersonality=yes
|
||||
SystemCallArchitectures=native
|
||||
SystemCallFilter=@system-service
|
||||
SystemCallErrorNumber=EPERM
|
||||
@@ -0,0 +1,14 @@
|
||||
[Unit]
|
||||
Description=Face unlock for KDE Plasma (socket)
|
||||
Documentation=man:plasma-face-unlock(1)
|
||||
|
||||
[Socket]
|
||||
# Everybody may connect. Who may ask for what is decided per request, by the
|
||||
# daemon, from the credentials the kernel reports for the other end.
|
||||
ListenStream=/run/plasma-face-unlock/socket
|
||||
SocketMode=0666
|
||||
DirectoryMode=0755
|
||||
RemoveOnStop=yes
|
||||
|
||||
[Install]
|
||||
WantedBy=sockets.target
|
||||
Reference in new issue
Block a user