[Unit] Description=Face unlock for KDE Plasma Documentation=man:face-unlock(1) Requires=face-unlockd.socket After=face-unlockd.socket [Service] Type=simple # Started by the socket, and gone again after a minute with nothing to do. ExecStart=@LIBEXECDIR@/face-unlockd StateDirectory=face-unlock StateDirectoryMode=0700 UMask=0077 # It reads a camera, runs two small networks and writes one directory. That is # all it is allowed to do. CapabilityBoundingSet=CAP_DAC_READ_SEARCH # The one capability: to reach a user's agent socket through their 0700 # runtime directory, to tell the bubble about a sudo scan. NoNewPrivileges=yes ProtectSystem=strict # To take back the failed login the lock screen counts for a face unlock. ReadWritePaths=-/run/faillock ProtectHome=read-only PrivateTmp=yes PrivateNetwork=yes RestrictAddressFamilies=AF_UNIX DevicePolicy=closed DeviceAllow=char-video4linux rw ProtectKernelTunables=yes ProtectKernelModules=yes ProtectKernelLogs=yes ProtectControlGroups=yes ProtectClock=yes ProtectHostname=yes RestrictNamespaces=yes RestrictRealtime=yes RestrictSUIDSGID=yes LockPersonality=yes SystemCallArchitectures=native SystemCallFilter=@system-service SystemCallErrorNumber=EPERM