fingerprintd/packaging/net.reactivated.Fprint.conf

21 lines
936 B
Text
Raw Normal View History

Become a daemon: a held session, a worker, and net.reactivated.Fprint The probe becomes the thing the plan was for. Three threads: the supplicant services QTEE's callbacks; the worker owns the sensor rail, the QTEE session and the trustlet and is the only thread that ever invokes it, so every enrolment and authentication is serialised by construction; the main thread runs the GLib loop and speaks fprintd's own D-Bus interface, never touching the trustlet directly. Session is the bring-up from a cold /dev/tee0 to a calibrated sensor, plus the enrol and verify loops as methods that take a cancel flag and progress callbacks. Worker is a job queue on a pthread with an 8 MiB stack -- musl's default is 128 KiB and the session keeps request buffers on the stack. Results come back through g_idle_add so signals are emitted on the thread that owns the connection. net.reactivated.Fprint is implemented rather than wrapped: Manager with GetDevices/GetDefaultDevice, Device with Claim/Release, EnrollStart/Stop, VerifyStart/Stop, ListEnrolledFingers and the three Delete variants, the three signals, and the five properties. Owning fprintd's name is what lets pam_fprintd, the Plasma KCM and fprintd-enroll work unmodified. Two honest limits. Authorisation is the conservative rule -- you may act on your own prints, root on anyone's -- because polkit is not in this milestone. And DeleteEnrolledFingers removes the finger's NAME only: FF_CMD_TA_REMOVE exists but its payload is not reverse-engineered, and guessing at a command that writes to the store is exactly how an index got invalidated earlier today. A deleted finger loses its name and stops being offered; its template still occupies a slot in the group. Logged as such. The finger-name map is written per user under the state directory, tmp-file and rename. An enrolment records the fid the trustlet reported in the touch event's response; if none was reported the finger cannot be named yet, and the daemon says so rather than inventing one. Verified on the phone as a systemd unit: owns the bus name, init chain complete, floor calibrated, ready.
2026-09-02 22:10:51 +02:00
<?xml version="1.0" encoding="UTF-8"?> <!--*-nxml-*-->
<!DOCTYPE busconfig PUBLIC "-//freedesktop//DTD D-BUS Bus Configuration 1.0//EN"
"http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd">
<!-- SPDX-License-Identifier: GPL-3.0-only
SPDX-FileCopyrightText: Copyright (C) 2026 Catcrafts®
fingerprintd owns fprintd's bus name so pam_fprintd, the Plasma KCM and
fprintd-enroll work unmodified. Same shape as fprintd's own policy: root
owns the name, anyone may call it, and the daemon enforces who may act on
whose prints.
Install: /usr/share/dbus-1/system.d/net.reactivated.Fprint.conf -->
<busconfig>
<policy user="root">
<allow own="net.reactivated.Fprint"/>
<allow send_destination="net.reactivated.Fprint"/>
</policy>
<policy context="default">
<allow send_destination="net.reactivated.Fprint"/>
<allow receive_sender="net.reactivated.Fprint"/>
</policy>
</busconfig>