This is a projection, not a development branch. The tree above was constructed from the internal source named below under a manifest that decides which paths may leave, then scanned as a whole tree rather than as a series of patches, and only then published. Public history starts here because the history before it was not admissible, and neither was the tree. What used to stand in this repository included a rescue copy of another machine, a directory of phone handoffs, deployment wired to one house, and a submodule pointing at a forge no stranger can reach. None of that was ever the product. It stays in the private forge, which is allowed to hold the whole working organism, and this is what was deliberately sent out instead. Three mechanisms produced this tree, in decreasing order of trust. A top-level path the manifest does not name never arrives at all, which is the one that catches directories nobody has thought of yet. Named internal files inside admitted roots are dropped. A short, reviewed table replaces deployment defaults that a public build must not carry -- an endpoint aimed at one LAN, a VPN profile belonging to one phone, packaging built from one checkout path. Everything after this commit is an ordinary publication with the same three trailers, so a force push stops being routine and starts meaning that something deliberate happened. The trailers bind the projection to its source without pretending the public SHA is the private one: same lineage, different tree, and the record says so. Source-Sha: 8f27b1e76a8fef560a336aba18e6990713ff1047 Policy-Sha: 6b261d2f3e6e1fb19874846ba4bb1dfe15565d25b8618c1c1afba0419c101d27 Tree-Digest: 18ec3563c5e5ef9a414993a9f6734b251ff9ed3cd56eebdd6cac01e45c6e3067
176 lines
5.2 KiB
QML
176 lines
5.2 KiB
QML
import qs
|
|
import qs.services
|
|
import qs.modules.common
|
|
import QtQuick
|
|
import Quickshell
|
|
import Quickshell.Io
|
|
import Quickshell.Services.Pam
|
|
|
|
Scope {
|
|
id: root
|
|
|
|
enum ActionEnum { Unlock, Poweroff, Reboot }
|
|
|
|
signal shouldReFocus()
|
|
signal unlocked(targetAction: var)
|
|
signal failed()
|
|
|
|
// These properties are in the context and not individual lock surfaces
|
|
// so all surfaces can share the same state.
|
|
property string currentText: ""
|
|
property bool unlockInProgress: false
|
|
property bool showFailure: false
|
|
property bool fingerprintsConfigured: false
|
|
property var targetAction: LockContext.ActionEnum.Unlock
|
|
property bool alsoInhibitIdle: false
|
|
|
|
// FingerprintPreview owns the FPC pulse and hold state for both lock and
|
|
// step-up. This context only exposes it to the lock surface; it never
|
|
// decides whether a hold unlocks the session.
|
|
readonly property bool provisionalFingerprintEnabled:
|
|
FingerprintPreview.previewEnabled
|
|
readonly property int provisionalFingerprintHoldMs:
|
|
FingerprintPreview.holdMs
|
|
readonly property bool provisionalFingerprintHolding:
|
|
FingerprintPreview.holding && FingerprintPreview.activePurpose === "lock"
|
|
readonly property bool provisionalFingerprintConfirmed:
|
|
FingerprintPreview.confirmed && FingerprintPreview.confirmedPurpose === "lock"
|
|
readonly property bool provisionalFingerprintPulseSeen: FingerprintPreview.pulseSeen
|
|
readonly property real provisionalFingerprintHoldProgress:
|
|
FingerprintPreview.activePurpose === "lock" ? FingerprintPreview.holdProgress : 0
|
|
|
|
function resetTargetAction() {
|
|
root.targetAction = LockContext.ActionEnum.Unlock;
|
|
}
|
|
|
|
function clearText() {
|
|
root.currentText = "";
|
|
}
|
|
|
|
function resetClearTimer() {
|
|
passwordClearTimer.restart();
|
|
}
|
|
|
|
function reset() {
|
|
root.resetTargetAction();
|
|
root.clearText();
|
|
root.unlockInProgress = false;
|
|
stopFingerPam();
|
|
root.resetProvisionalFingerprint();
|
|
}
|
|
|
|
function beginProvisionalFingerprintHold() {
|
|
FingerprintPreview.beginHold("lock");
|
|
}
|
|
|
|
function cancelProvisionalFingerprintHold() {
|
|
FingerprintPreview.cancelHold("lock");
|
|
}
|
|
|
|
function confirmProvisionalFingerprintHold() {
|
|
FingerprintPreview.confirmHold("lock");
|
|
}
|
|
|
|
// Called by the diagnostic `fingerprint.signal` IPC seam. It reaches the
|
|
// same one-owner state as the root-owned FPC producer record.
|
|
function noteProvisionalFingerprintPulse() {
|
|
return FingerprintPreview.notePulse();
|
|
}
|
|
|
|
function resetProvisionalFingerprint() {
|
|
FingerprintPreview.reset("lock");
|
|
}
|
|
|
|
Timer {
|
|
id: passwordClearTimer
|
|
interval: 10000
|
|
onTriggered: {
|
|
root.reset();
|
|
}
|
|
}
|
|
|
|
onCurrentTextChanged: {
|
|
if (currentText.length > 0) {
|
|
showFailure = false;
|
|
GlobalStates.screenUnlockFailed = false;
|
|
}
|
|
GlobalStates.screenLockContainsCharacters = currentText.length > 0;
|
|
passwordClearTimer.restart();
|
|
}
|
|
|
|
function tryUnlock(alsoInhibitIdle = false) {
|
|
root.alsoInhibitIdle = alsoInhibitIdle;
|
|
root.unlockInProgress = true;
|
|
pam.start();
|
|
}
|
|
|
|
function tryFingerUnlock() {
|
|
if (root.fingerprintsConfigured) {
|
|
fingerPam.start();
|
|
}
|
|
}
|
|
|
|
function stopFingerPam() {
|
|
if (fingerPam.active) {
|
|
fingerPam.abort();
|
|
}
|
|
}
|
|
|
|
Process {
|
|
id: fingerprintCheckProc
|
|
running: true
|
|
command: ["bash", "-c", "fprintd-list $(whoami)"]
|
|
stdout: StdioCollector {
|
|
id: fingerprintOutputCollector
|
|
onStreamFinished: {
|
|
root.fingerprintsConfigured = fingerprintOutputCollector.text.includes("Fingerprints for user");
|
|
}
|
|
}
|
|
onExited: (exitCode, exitStatus) => {
|
|
if (exitCode !== 0) {
|
|
// console.warn("[LockContext] fprintd-list command exited with error:", exitCode, exitStatus);
|
|
root.fingerprintsConfigured = false;
|
|
}
|
|
}
|
|
}
|
|
|
|
PamContext {
|
|
id: pam
|
|
|
|
// pam_unix will ask for a response for the password prompt
|
|
onPamMessage: {
|
|
if (this.responseRequired) {
|
|
this.respond(root.currentText);
|
|
}
|
|
}
|
|
|
|
// pam_unix won't send any important messages so all we need is the completion status.
|
|
onCompleted: result => {
|
|
if (result == PamResult.Success) {
|
|
root.unlocked(root.targetAction);
|
|
stopFingerPam();
|
|
} else {
|
|
root.clearText();
|
|
root.unlockInProgress = false;
|
|
GlobalStates.screenUnlockFailed = true;
|
|
root.showFailure = true;
|
|
}
|
|
}
|
|
}
|
|
|
|
PamContext {
|
|
id: fingerPam
|
|
|
|
configDirectory: "pam"
|
|
config: "fprintd.conf"
|
|
|
|
onCompleted: result => {
|
|
if (result == PamResult.Success) {
|
|
root.unlocked(root.targetAction);
|
|
stopFingerPam();
|
|
} else if (result == PamResult.Error) { // if timeout or etc..
|
|
tryFingerUnlock()
|
|
}
|
|
}
|
|
}
|
|
}
|