Files
face-unlock/res/systemd/face-unlockd.service

43 lines
1.2 KiB
Desktop File

[Unit]
Description=Face unlock
Documentation=man:face-unlock(1)
Requires=face-unlockd.socket
After=face-unlockd.socket
[Service]
Type=simple
# Started by the socket, and gone again after a minute with nothing to do.
ExecStart=@LIBEXECDIR@/face-unlockd
StateDirectory=face-unlock
StateDirectoryMode=0700
UMask=0077
# It reads a camera, runs two small networks and writes one directory. That is
# all it is allowed to do.
CapabilityBoundingSet=CAP_DAC_READ_SEARCH
# The one capability: to reach a user's agent socket through their 0700
# runtime directory, to tell the bubble about a sudo scan.
NoNewPrivileges=yes
ProtectSystem=strict
# To take back the failed login the lock screen counts for a face unlock.
ReadWritePaths=-/run/faillock
ProtectHome=read-only
PrivateTmp=yes
PrivateNetwork=yes
RestrictAddressFamilies=AF_UNIX
DevicePolicy=closed
DeviceAllow=char-video4linux rw
ProtectKernelTunables=yes
ProtectKernelModules=yes
ProtectKernelLogs=yes
ProtectControlGroups=yes
ProtectClock=yes
ProtectHostname=yes
RestrictNamespaces=yes
RestrictRealtime=yes
RestrictSUIDSGID=yes
LockPersonality=yes
SystemCallArchitectures=native
SystemCallFilter=@system-service
SystemCallErrorNumber=EPERM