Give a finger a meaning beyond "it was you"
The trustlet has always reported WHICH finger matched and the daemon only ever
used it to answer yes. A table in /etc/fingerprintd/actions.conf now gives each
finger a meaning: run a command as root, tell the user's session, or report
no-match while doing one of those anyway -- which is duress, where the phone
should look like it simply did not recognise the finger.
Two rules shaped the design.
Root does not launch applications. The daemon has no session bus, no display
and no user environment, so a `session` rule carries no command at all: the
daemon emits net.catcrafts.Fingerprintd1.FingerMatched(finger, uid) and an
agent in the user's own session decides what that means from the user's own
configuration. The only commands in the file are ones root is meant to run.
Which makes the file a root shell, and the parser treats it as one. It is
refused outright unless root owns it and nobody else can write it, group
included. A malformed line rejects the WHOLE file rather than being skipped:
applying the prefix would leave a policy nobody wrote, and the missing half
could be the one that mattered. That property is tested, and the test caught it
being false the first time -- rules accumulated before the bad line survived
the rejection.
A system command must be an absolute path, because resolving a bare name
through PATH makes what root runs depend on an environment this daemon does not
control. It is double-forked with a scrubbed environment so an action may
outlive the daemon (a reboot) without ever stalling the worker thread that is
the only thread allowed to touch the trustlet.
Ordering is deliberate: the verdict override happens before the client is told,
because that is the point of duress; the session signal and the root command
happen after, on the same principle that keeps the harvest and the save off the
unlock path.
No actions.conf ships. An example goes to /usr/share/doc, because shipping a
root shell nobody asked for is not a default.
Not yet exercised on hardware.
2026-09-05 05:12:41 +02:00
|
|
|
// SPDX-License-Identifier: GPL-3.0-only
|
|
|
|
|
// SPDX-FileCopyrightText: Copyright (C) 2026 Catcrafts®
|
|
|
|
|
|
|
|
|
|
// lint-disable-file fixed-width-types
|
|
|
|
|
/*
|
|
|
|
|
Fingerprintd:Actions unit tests.
|
|
|
|
|
|
|
|
|
|
This table decides what root executes when a finger touches the sensor, so the
|
|
|
|
|
tests here are mostly about REFUSAL. The load-bearing properties:
|
|
|
|
|
|
|
|
|
|
* a file anyone but root can write is rejected before a single rule is read,
|
|
|
|
|
* a malformed rule rejects the WHOLE file rather than being skipped -- a
|
|
|
|
|
half-applied policy is the dangerous outcome, not the safe one,
|
2026-09-05 05:23:40 +02:00
|
|
|
* a command must be an absolute path, because resolving a bare name through
|
|
|
|
|
PATH would make what root runs depend on an environment this daemon does
|
|
|
|
|
not control,
|
Give a finger a meaning beyond "it was you"
The trustlet has always reported WHICH finger matched and the daemon only ever
used it to answer yes. A table in /etc/fingerprintd/actions.conf now gives each
finger a meaning: run a command as root, tell the user's session, or report
no-match while doing one of those anyway -- which is duress, where the phone
should look like it simply did not recognise the finger.
Two rules shaped the design.
Root does not launch applications. The daemon has no session bus, no display
and no user environment, so a `session` rule carries no command at all: the
daemon emits net.catcrafts.Fingerprintd1.FingerMatched(finger, uid) and an
agent in the user's own session decides what that means from the user's own
configuration. The only commands in the file are ones root is meant to run.
Which makes the file a root shell, and the parser treats it as one. It is
refused outright unless root owns it and nobody else can write it, group
included. A malformed line rejects the WHOLE file rather than being skipped:
applying the prefix would leave a policy nobody wrote, and the missing half
could be the one that mattered. That property is tested, and the test caught it
being false the first time -- rules accumulated before the bad line survived
the rejection.
A system command must be an absolute path, because resolving a bare name
through PATH makes what root runs depend on an environment this daemon does not
control. It is double-forked with a scrubbed environment so an action may
outlive the daemon (a reboot) without ever stalling the worker thread that is
the only thread allowed to touch the trustlet.
Ordering is deliberate: the verdict override happens before the client is told,
because that is the point of duress; the session signal and the root command
happen after, on the same principle that keeps the harvest and the save off the
unlock path.
No actions.conf ships. An example goes to /usr/share/doc, because shipping a
root shell nobody asked for is not a default.
Not yet exercised on hardware.
2026-09-05 05:12:41 +02:00
|
|
|
* and no rule at all means no behaviour change, which is what keeps the
|
|
|
|
|
feature absent until someone configures it.
|
|
|
|
|
*/
|
|
|
|
|
import std;
|
|
|
|
|
import Fingerprintd;
|
|
|
|
|
|
|
|
|
|
using namespace fingerprintd::actions;
|
|
|
|
|
using fingerprintd::store::Finger;
|
|
|
|
|
|
|
|
|
|
namespace {
|
|
|
|
|
int Failures = 0;
|
|
|
|
|
void Check(bool cond, std::string_view msg) {
|
|
|
|
|
if (!cond) {
|
|
|
|
|
std::println(std::cerr, "FAIL: {}", msg);
|
|
|
|
|
++Failures;
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
Parsed P(std::string_view t, bool rootOnly = true) { return Parse(t, rootOnly); }
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
int main() {
|
|
|
|
|
// ---- the file's own permissions are checked before its contents
|
|
|
|
|
{
|
2026-09-05 05:23:40 +02:00
|
|
|
Parsed p = P("right-index-finger /bin/true", /*rootOnly*/ false);
|
Give a finger a meaning beyond "it was you"
The trustlet has always reported WHICH finger matched and the daemon only ever
used it to answer yes. A table in /etc/fingerprintd/actions.conf now gives each
finger a meaning: run a command as root, tell the user's session, or report
no-match while doing one of those anyway -- which is duress, where the phone
should look like it simply did not recognise the finger.
Two rules shaped the design.
Root does not launch applications. The daemon has no session bus, no display
and no user environment, so a `session` rule carries no command at all: the
daemon emits net.catcrafts.Fingerprintd1.FingerMatched(finger, uid) and an
agent in the user's own session decides what that means from the user's own
configuration. The only commands in the file are ones root is meant to run.
Which makes the file a root shell, and the parser treats it as one. It is
refused outright unless root owns it and nobody else can write it, group
included. A malformed line rejects the WHOLE file rather than being skipped:
applying the prefix would leave a policy nobody wrote, and the missing half
could be the one that mattered. That property is tested, and the test caught it
being false the first time -- rules accumulated before the bad line survived
the rejection.
A system command must be an absolute path, because resolving a bare name
through PATH makes what root runs depend on an environment this daemon does not
control. It is double-forked with a scrubbed environment so an action may
outlive the daemon (a reboot) without ever stalling the worker thread that is
the only thread allowed to touch the trustlet.
Ordering is deliberate: the verdict override happens before the client is told,
because that is the point of duress; the session signal and the root command
happen after, on the same principle that keeps the harvest and the save off the
unlock path.
No actions.conf ships. An example goes to /usr/share/doc, because shipping a
root shell nobody asked for is not a default.
Not yet exercised on hardware.
2026-09-05 05:12:41 +02:00
|
|
|
Check(!p.Ok(), "a file others can write is refused");
|
|
|
|
|
Check(p.error == Error::NotWritableOnlyByRoot, "and refused for that reason");
|
|
|
|
|
Check(p.line == 0, "the file is the fault, not a line");
|
|
|
|
|
Check(p.rules.empty(), "nothing is parsed out of it");
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// ---- no config is not an error; it is the feature being off
|
|
|
|
|
{
|
|
|
|
|
Parsed p = P("");
|
|
|
|
|
Check(p.Ok() && p.rules.empty(), "an empty file yields no rules");
|
|
|
|
|
Parsed c = P("# nothing but a comment\n\n # indented\n");
|
|
|
|
|
Check(c.Ok() && c.rules.empty(), "comments and blank lines are ignored");
|
|
|
|
|
}
|
|
|
|
|
|
2026-09-05 05:23:40 +02:00
|
|
|
// ---- the three shapes a line can take
|
Give a finger a meaning beyond "it was you"
The trustlet has always reported WHICH finger matched and the daemon only ever
used it to answer yes. A table in /etc/fingerprintd/actions.conf now gives each
finger a meaning: run a command as root, tell the user's session, or report
no-match while doing one of those anyway -- which is duress, where the phone
should look like it simply did not recognise the finger.
Two rules shaped the design.
Root does not launch applications. The daemon has no session bus, no display
and no user environment, so a `session` rule carries no command at all: the
daemon emits net.catcrafts.Fingerprintd1.FingerMatched(finger, uid) and an
agent in the user's own session decides what that means from the user's own
configuration. The only commands in the file are ones root is meant to run.
Which makes the file a root shell, and the parser treats it as one. It is
refused outright unless root owns it and nobody else can write it, group
included. A malformed line rejects the WHOLE file rather than being skipped:
applying the prefix would leave a policy nobody wrote, and the missing half
could be the one that mattered. That property is tested, and the test caught it
being false the first time -- rules accumulated before the bad line survived
the rejection.
A system command must be an absolute path, because resolving a bare name
through PATH makes what root runs depend on an environment this daemon does not
control. It is double-forked with a scrubbed environment so an action may
outlive the daemon (a reboot) without ever stalling the worker thread that is
the only thread allowed to touch the trustlet.
Ordering is deliberate: the verdict override happens before the client is told,
because that is the point of duress; the session signal and the root command
happen after, on the same principle that keeps the harvest and the save off the
unlock path.
No actions.conf ships. An example goes to /usr/share/doc, because shipping a
root shell nobody asked for is not a default.
Not yet exercised on hardware.
2026-09-05 05:12:41 +02:00
|
|
|
{
|
2026-09-05 05:23:40 +02:00
|
|
|
Parsed p = P("# finger what\n"
|
|
|
|
|
"right-ring-finger /usr/bin/logger -t fp ring\n"
|
|
|
|
|
"left-little-finger no-unlock /etc/fingerprintd/panic.sh\n"
|
|
|
|
|
"left-thumb no-unlock\n");
|
Give a finger a meaning beyond "it was you"
The trustlet has always reported WHICH finger matched and the daemon only ever
used it to answer yes. A table in /etc/fingerprintd/actions.conf now gives each
finger a meaning: run a command as root, tell the user's session, or report
no-match while doing one of those anyway -- which is duress, where the phone
should look like it simply did not recognise the finger.
Two rules shaped the design.
Root does not launch applications. The daemon has no session bus, no display
and no user environment, so a `session` rule carries no command at all: the
daemon emits net.catcrafts.Fingerprintd1.FingerMatched(finger, uid) and an
agent in the user's own session decides what that means from the user's own
configuration. The only commands in the file are ones root is meant to run.
Which makes the file a root shell, and the parser treats it as one. It is
refused outright unless root owns it and nobody else can write it, group
included. A malformed line rejects the WHOLE file rather than being skipped:
applying the prefix would leave a policy nobody wrote, and the missing half
could be the one that mattered. That property is tested, and the test caught it
being false the first time -- rules accumulated before the bad line survived
the rejection.
A system command must be an absolute path, because resolving a bare name
through PATH makes what root runs depend on an environment this daemon does not
control. It is double-forked with a scrubbed environment so an action may
outlive the daemon (a reboot) without ever stalling the worker thread that is
the only thread allowed to touch the trustlet.
Ordering is deliberate: the verdict override happens before the client is told,
because that is the point of duress; the session signal and the root command
happen after, on the same principle that keeps the harvest and the save off the
unlock path.
No actions.conf ships. An example goes to /usr/share/doc, because shipping a
root shell nobody asked for is not a default.
Not yet exercised on hardware.
2026-09-05 05:12:41 +02:00
|
|
|
Check(p.Ok(), "a valid file parses");
|
2026-09-05 05:23:40 +02:00
|
|
|
Check(p.rules.size() == 3, "all three rules");
|
|
|
|
|
|
|
|
|
|
const Rule* ring = Find(p.rules, Finger::RightRing);
|
|
|
|
|
Check(ring && ring->unlocks, "a command-only finger still unlocks");
|
|
|
|
|
Check(ring && ring->command == "/usr/bin/logger -t fp ring",
|
|
|
|
|
"and the command arrives whole, spaces and all");
|
|
|
|
|
|
|
|
|
|
const Rule* duress = Find(p.rules, Finger::LeftLittle);
|
|
|
|
|
Check(duress && !duress->unlocks, "no-unlock is recorded");
|
|
|
|
|
Check(duress && duress->command == "/etc/fingerprintd/panic.sh",
|
|
|
|
|
"alongside its command -- the duress case needs both");
|
|
|
|
|
|
|
|
|
|
const Rule* thumb = Find(p.rules, Finger::LeftThumb);
|
|
|
|
|
Check(thumb && !thumb->unlocks, "no-unlock alone is a complete rule");
|
|
|
|
|
Check(thumb && thumb->command.empty(), "with no command");
|
|
|
|
|
|
|
|
|
|
Check(Find(p.rules, Finger::RightIndex) == nullptr,
|
Give a finger a meaning beyond "it was you"
The trustlet has always reported WHICH finger matched and the daemon only ever
used it to answer yes. A table in /etc/fingerprintd/actions.conf now gives each
finger a meaning: run a command as root, tell the user's session, or report
no-match while doing one of those anyway -- which is duress, where the phone
should look like it simply did not recognise the finger.
Two rules shaped the design.
Root does not launch applications. The daemon has no session bus, no display
and no user environment, so a `session` rule carries no command at all: the
daemon emits net.catcrafts.Fingerprintd1.FingerMatched(finger, uid) and an
agent in the user's own session decides what that means from the user's own
configuration. The only commands in the file are ones root is meant to run.
Which makes the file a root shell, and the parser treats it as one. It is
refused outright unless root owns it and nobody else can write it, group
included. A malformed line rejects the WHOLE file rather than being skipped:
applying the prefix would leave a policy nobody wrote, and the missing half
could be the one that mattered. That property is tested, and the test caught it
being false the first time -- rules accumulated before the bad line survived
the rejection.
A system command must be an absolute path, because resolving a bare name
through PATH makes what root runs depend on an environment this daemon does not
control. It is double-forked with a scrubbed environment so an action may
outlive the daemon (a reboot) without ever stalling the worker thread that is
the only thread allowed to touch the trustlet.
Ordering is deliberate: the verdict override happens before the client is told,
because that is the point of duress; the session signal and the root command
happen after, on the same principle that keeps the harvest and the save off the
unlock path.
No actions.conf ships. An example goes to /usr/share/doc, because shipping a
root shell nobody asked for is not a default.
Not yet exercised on hardware.
2026-09-05 05:12:41 +02:00
|
|
|
"a finger with no rule has no rule");
|
|
|
|
|
}
|
|
|
|
|
|
2026-09-05 05:23:40 +02:00
|
|
|
// ---- a command that merely STARTS like the keyword is a command
|
Give a finger a meaning beyond "it was you"
The trustlet has always reported WHICH finger matched and the daemon only ever
used it to answer yes. A table in /etc/fingerprintd/actions.conf now gives each
finger a meaning: run a command as root, tell the user's session, or report
no-match while doing one of those anyway -- which is duress, where the phone
should look like it simply did not recognise the finger.
Two rules shaped the design.
Root does not launch applications. The daemon has no session bus, no display
and no user environment, so a `session` rule carries no command at all: the
daemon emits net.catcrafts.Fingerprintd1.FingerMatched(finger, uid) and an
agent in the user's own session decides what that means from the user's own
configuration. The only commands in the file are ones root is meant to run.
Which makes the file a root shell, and the parser treats it as one. It is
refused outright unless root owns it and nobody else can write it, group
included. A malformed line rejects the WHOLE file rather than being skipped:
applying the prefix would leave a policy nobody wrote, and the missing half
could be the one that mattered. That property is tested, and the test caught it
being false the first time -- rules accumulated before the bad line survived
the rejection.
A system command must be an absolute path, because resolving a bare name
through PATH makes what root runs depend on an environment this daemon does not
control. It is double-forked with a scrubbed environment so an action may
outlive the daemon (a reboot) without ever stalling the worker thread that is
the only thread allowed to touch the trustlet.
Ordering is deliberate: the verdict override happens before the client is told,
because that is the point of duress; the session signal and the root command
happen after, on the same principle that keeps the harvest and the save off the
unlock path.
No actions.conf ships. An example goes to /usr/share/doc, because shipping a
root shell nobody asked for is not a default.
Not yet exercised on hardware.
2026-09-05 05:12:41 +02:00
|
|
|
{
|
2026-09-05 05:23:40 +02:00
|
|
|
Parsed p = P("left-index-finger /usr/local/bin/no-unlock-helper\n");
|
|
|
|
|
Check(p.Ok(), "parses");
|
|
|
|
|
const Rule* r = Find(p.rules, Finger::LeftIndex);
|
|
|
|
|
Check(r && r->unlocks, "the finger still unlocks");
|
|
|
|
|
Check(r && r->command == "/usr/local/bin/no-unlock-helper",
|
|
|
|
|
"and the path was not mistaken for the keyword");
|
Give a finger a meaning beyond "it was you"
The trustlet has always reported WHICH finger matched and the daemon only ever
used it to answer yes. A table in /etc/fingerprintd/actions.conf now gives each
finger a meaning: run a command as root, tell the user's session, or report
no-match while doing one of those anyway -- which is duress, where the phone
should look like it simply did not recognise the finger.
Two rules shaped the design.
Root does not launch applications. The daemon has no session bus, no display
and no user environment, so a `session` rule carries no command at all: the
daemon emits net.catcrafts.Fingerprintd1.FingerMatched(finger, uid) and an
agent in the user's own session decides what that means from the user's own
configuration. The only commands in the file are ones root is meant to run.
Which makes the file a root shell, and the parser treats it as one. It is
refused outright unless root owns it and nobody else can write it, group
included. A malformed line rejects the WHOLE file rather than being skipped:
applying the prefix would leave a policy nobody wrote, and the missing half
could be the one that mattered. That property is tested, and the test caught it
being false the first time -- rules accumulated before the bad line survived
the rejection.
A system command must be an absolute path, because resolving a bare name
through PATH makes what root runs depend on an environment this daemon does not
control. It is double-forked with a scrubbed environment so an action may
outlive the daemon (a reboot) without ever stalling the worker thread that is
the only thread allowed to touch the trustlet.
Ordering is deliberate: the verdict override happens before the client is told,
because that is the point of duress; the session signal and the root command
happen after, on the same principle that keeps the harvest and the save off the
unlock path.
No actions.conf ships. An example goes to /usr/share/doc, because shipping a
root shell nobody asked for is not a default.
Not yet exercised on hardware.
2026-09-05 05:12:41 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// ---- every rejection rejects the whole file
|
|
|
|
|
{
|
|
|
|
|
struct Case { std::string_view text; Error want; std::string_view why; };
|
|
|
|
|
const Case cases[] = {
|
2026-09-05 05:23:40 +02:00
|
|
|
{ "not-a-finger /bin/true\n", Error::UnknownFinger,
|
Give a finger a meaning beyond "it was you"
The trustlet has always reported WHICH finger matched and the daemon only ever
used it to answer yes. A table in /etc/fingerprintd/actions.conf now gives each
finger a meaning: run a command as root, tell the user's session, or report
no-match while doing one of those anyway -- which is duress, where the phone
should look like it simply did not recognise the finger.
Two rules shaped the design.
Root does not launch applications. The daemon has no session bus, no display
and no user environment, so a `session` rule carries no command at all: the
daemon emits net.catcrafts.Fingerprintd1.FingerMatched(finger, uid) and an
agent in the user's own session decides what that means from the user's own
configuration. The only commands in the file are ones root is meant to run.
Which makes the file a root shell, and the parser treats it as one. It is
refused outright unless root owns it and nobody else can write it, group
included. A malformed line rejects the WHOLE file rather than being skipped:
applying the prefix would leave a policy nobody wrote, and the missing half
could be the one that mattered. That property is tested, and the test caught it
being false the first time -- rules accumulated before the bad line survived
the rejection.
A system command must be an absolute path, because resolving a bare name
through PATH makes what root runs depend on an environment this daemon does not
control. It is double-forked with a scrubbed environment so an action may
outlive the daemon (a reboot) without ever stalling the worker thread that is
the only thread allowed to touch the trustlet.
Ordering is deliberate: the verdict override happens before the client is told,
because that is the point of duress; the session signal and the root command
happen after, on the same principle that keeps the harvest and the save off the
unlock path.
No actions.conf ships. An example goes to /usr/share/doc, because shipping a
root shell nobody asked for is not a default.
Not yet exercised on hardware.
2026-09-05 05:12:41 +02:00
|
|
|
"an unknown finger name" },
|
2026-09-05 05:23:40 +02:00
|
|
|
{ "right-index-finger\n", Error::NothingToDo,
|
|
|
|
|
"a finger on its own, which the signal already covers" },
|
|
|
|
|
{ "right-index-finger reboot\n", Error::RelativeCommand,
|
Give a finger a meaning beyond "it was you"
The trustlet has always reported WHICH finger matched and the daemon only ever
used it to answer yes. A table in /etc/fingerprintd/actions.conf now gives each
finger a meaning: run a command as root, tell the user's session, or report
no-match while doing one of those anyway -- which is duress, where the phone
should look like it simply did not recognise the finger.
Two rules shaped the design.
Root does not launch applications. The daemon has no session bus, no display
and no user environment, so a `session` rule carries no command at all: the
daemon emits net.catcrafts.Fingerprintd1.FingerMatched(finger, uid) and an
agent in the user's own session decides what that means from the user's own
configuration. The only commands in the file are ones root is meant to run.
Which makes the file a root shell, and the parser treats it as one. It is
refused outright unless root owns it and nobody else can write it, group
included. A malformed line rejects the WHOLE file rather than being skipped:
applying the prefix would leave a policy nobody wrote, and the missing half
could be the one that mattered. That property is tested, and the test caught it
being false the first time -- rules accumulated before the bad line survived
the rejection.
A system command must be an absolute path, because resolving a bare name
through PATH makes what root runs depend on an environment this daemon does not
control. It is double-forked with a scrubbed environment so an action may
outlive the daemon (a reboot) without ever stalling the worker thread that is
the only thread allowed to touch the trustlet.
Ordering is deliberate: the verdict override happens before the client is told,
because that is the point of duress; the session signal and the root command
happen after, on the same principle that keeps the harvest and the save off the
unlock path.
No actions.conf ships. An example goes to /usr/share/doc, because shipping a
root shell nobody asked for is not a default.
Not yet exercised on hardware.
2026-09-05 05:12:41 +02:00
|
|
|
"a command that is not an absolute path" },
|
2026-09-05 05:23:40 +02:00
|
|
|
{ "right-index-finger no-unlock reboot\n", Error::RelativeCommand,
|
|
|
|
|
"a relative command after the keyword" },
|
|
|
|
|
{ "left-thumb no-unlock\nleft-thumb /bin/true\n",
|
Give a finger a meaning beyond "it was you"
The trustlet has always reported WHICH finger matched and the daemon only ever
used it to answer yes. A table in /etc/fingerprintd/actions.conf now gives each
finger a meaning: run a command as root, tell the user's session, or report
no-match while doing one of those anyway -- which is duress, where the phone
should look like it simply did not recognise the finger.
Two rules shaped the design.
Root does not launch applications. The daemon has no session bus, no display
and no user environment, so a `session` rule carries no command at all: the
daemon emits net.catcrafts.Fingerprintd1.FingerMatched(finger, uid) and an
agent in the user's own session decides what that means from the user's own
configuration. The only commands in the file are ones root is meant to run.
Which makes the file a root shell, and the parser treats it as one. It is
refused outright unless root owns it and nobody else can write it, group
included. A malformed line rejects the WHOLE file rather than being skipped:
applying the prefix would leave a policy nobody wrote, and the missing half
could be the one that mattered. That property is tested, and the test caught it
being false the first time -- rules accumulated before the bad line survived
the rejection.
A system command must be an absolute path, because resolving a bare name
through PATH makes what root runs depend on an environment this daemon does not
control. It is double-forked with a scrubbed environment so an action may
outlive the daemon (a reboot) without ever stalling the worker thread that is
the only thread allowed to touch the trustlet.
Ordering is deliberate: the verdict override happens before the client is told,
because that is the point of duress; the session signal and the root command
happen after, on the same principle that keeps the harvest and the save off the
unlock path.
No actions.conf ships. An example goes to /usr/share/doc, because shipping a
root shell nobody asked for is not a default.
Not yet exercised on hardware.
2026-09-05 05:12:41 +02:00
|
|
|
Error::DuplicateFinger, "two rules for one finger" },
|
|
|
|
|
};
|
|
|
|
|
for (const Case& c : cases) {
|
|
|
|
|
Parsed p = P(c.text);
|
|
|
|
|
Check(!p.Ok(), std::format("rejected: {}", c.why));
|
|
|
|
|
Check(p.error == c.want, std::format("for the right reason: {}", c.why));
|
|
|
|
|
Check(p.rules.empty(),
|
|
|
|
|
std::format("and yields NO rules at all: {}", c.why));
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// ---- a valid rule before a bad one is discarded with it
|
|
|
|
|
{
|
2026-09-05 05:23:40 +02:00
|
|
|
Parsed p = P("right-index-finger no-unlock\n"
|
|
|
|
|
"left-thumb reboot\n");
|
Give a finger a meaning beyond "it was you"
The trustlet has always reported WHICH finger matched and the daemon only ever
used it to answer yes. A table in /etc/fingerprintd/actions.conf now gives each
finger a meaning: run a command as root, tell the user's session, or report
no-match while doing one of those anyway -- which is duress, where the phone
should look like it simply did not recognise the finger.
Two rules shaped the design.
Root does not launch applications. The daemon has no session bus, no display
and no user environment, so a `session` rule carries no command at all: the
daemon emits net.catcrafts.Fingerprintd1.FingerMatched(finger, uid) and an
agent in the user's own session decides what that means from the user's own
configuration. The only commands in the file are ones root is meant to run.
Which makes the file a root shell, and the parser treats it as one. It is
refused outright unless root owns it and nobody else can write it, group
included. A malformed line rejects the WHOLE file rather than being skipped:
applying the prefix would leave a policy nobody wrote, and the missing half
could be the one that mattered. That property is tested, and the test caught it
being false the first time -- rules accumulated before the bad line survived
the rejection.
A system command must be an absolute path, because resolving a bare name
through PATH makes what root runs depend on an environment this daemon does not
control. It is double-forked with a scrubbed environment so an action may
outlive the daemon (a reboot) without ever stalling the worker thread that is
the only thread allowed to touch the trustlet.
Ordering is deliberate: the verdict override happens before the client is told,
because that is the point of duress; the session signal and the root command
happen after, on the same principle that keeps the harvest and the save off the
unlock path.
No actions.conf ships. An example goes to /usr/share/doc, because shipping a
root shell nobody asked for is not a default.
Not yet exercised on hardware.
2026-09-05 05:12:41 +02:00
|
|
|
Check(!p.Ok(), "the file fails");
|
|
|
|
|
Check(p.line == 2, "on the offending line");
|
|
|
|
|
Check(p.rules.empty(),
|
|
|
|
|
"and the GOOD rule above it is discarded too -- a half-applied "
|
|
|
|
|
"policy is the dangerous outcome");
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// ---- every Error has a description; a switch that forgets one shows up here
|
|
|
|
|
{
|
|
|
|
|
const Error all[] = { Error::None, Error::NotWritableOnlyByRoot, Error::UnknownFinger,
|
2026-09-05 05:23:40 +02:00
|
|
|
Error::RelativeCommand, Error::NothingToDo,
|
|
|
|
|
Error::DuplicateFinger };
|
Give a finger a meaning beyond "it was you"
The trustlet has always reported WHICH finger matched and the daemon only ever
used it to answer yes. A table in /etc/fingerprintd/actions.conf now gives each
finger a meaning: run a command as root, tell the user's session, or report
no-match while doing one of those anyway -- which is duress, where the phone
should look like it simply did not recognise the finger.
Two rules shaped the design.
Root does not launch applications. The daemon has no session bus, no display
and no user environment, so a `session` rule carries no command at all: the
daemon emits net.catcrafts.Fingerprintd1.FingerMatched(finger, uid) and an
agent in the user's own session decides what that means from the user's own
configuration. The only commands in the file are ones root is meant to run.
Which makes the file a root shell, and the parser treats it as one. It is
refused outright unless root owns it and nobody else can write it, group
included. A malformed line rejects the WHOLE file rather than being skipped:
applying the prefix would leave a policy nobody wrote, and the missing half
could be the one that mattered. That property is tested, and the test caught it
being false the first time -- rules accumulated before the bad line survived
the rejection.
A system command must be an absolute path, because resolving a bare name
through PATH makes what root runs depend on an environment this daemon does not
control. It is double-forked with a scrubbed environment so an action may
outlive the daemon (a reboot) without ever stalling the worker thread that is
the only thread allowed to touch the trustlet.
Ordering is deliberate: the verdict override happens before the client is told,
because that is the point of duress; the session signal and the root command
happen after, on the same principle that keeps the harvest and the save off the
unlock path.
No actions.conf ships. An example goes to /usr/share/doc, because shipping a
root shell nobody asked for is not a default.
Not yet exercised on hardware.
2026-09-05 05:12:41 +02:00
|
|
|
for (Error e : all)
|
|
|
|
|
Check(Describe(e) != "unknown", "every error describes itself");
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if (Failures == 0) std::println("Actions: all checks passed");
|
|
|
|
|
return Failures == 0 ? 0 : 1;
|
|
|
|
|
}
|