feat: add plasma-face-unlock

This commit is contained in:
Felitendo committed 2026-09-22 19:39:04 +02:00
commit f671acc93b
105 files changed
+13862

No files matched your search

@@ -0,0 +1,17 @@
[Unit]
Description=Face unlock for KDE Plasma (lock screen and bubble)
Documentation=man:plasma-face-unlock(1)
PartOf=graphical-session.target
After=graphical-session.target
# Plasma on Wayland. The bubble is a layer-shell surface, and there is no such
# thing on X11.
ConditionEnvironment=WAYLAND_DISPLAY
[Service]
ExecStart=@LIBEXECDIR@/plasma-face-unlock-agent
Restart=on-failure
RestartSec=3
Slice=session.slice
[Install]
WantedBy=graphical-session.target
+40
View File
@@ -0,0 +1,40 @@
[Unit]
Description=Face unlock for KDE Plasma
Documentation=man:plasma-face-unlock(1)
Requires=plasma-face-unlockd.socket
After=plasma-face-unlockd.socket
[Service]
Type=simple
# Started by the socket, and gone again after a minute with nothing to do.
ExecStart=@LIBEXECDIR@/plasma-face-unlockd
StateDirectory=plasma-face-unlock
StateDirectoryMode=0700
UMask=0077
# It reads a camera, runs two small networks and writes one directory. That is
# all it is allowed to do.
CapabilityBoundingSet=CAP_DAC_READ_SEARCH
# The one capability: to reach a user's agent socket through their 0700
# runtime directory, to tell the bubble about a sudo scan.
NoNewPrivileges=yes
ProtectSystem=strict
ProtectHome=read-only
PrivateTmp=yes
PrivateNetwork=yes
RestrictAddressFamilies=AF_UNIX
DevicePolicy=closed
DeviceAllow=char-video4linux rw
ProtectKernelTunables=yes
ProtectKernelModules=yes
ProtectKernelLogs=yes
ProtectControlGroups=yes
ProtectClock=yes
ProtectHostname=yes
RestrictNamespaces=yes
RestrictRealtime=yes
RestrictSUIDSGID=yes
LockPersonality=yes
SystemCallArchitectures=native
SystemCallFilter=@system-service
SystemCallErrorNumber=EPERM
+14
View File
@@ -0,0 +1,14 @@
[Unit]
Description=Face unlock for KDE Plasma (socket)
Documentation=man:plasma-face-unlock(1)
[Socket]
# Everybody may connect. Who may ask for what is decided per request, by the
# daemon, from the credentials the kernel reports for the other end.
ListenStream=/run/plasma-face-unlock/socket
SocketMode=0666
DirectoryMode=0755
RemoveOnStop=yes
[Install]
WantedBy=sockets.target