Name: linux-hello Version: 0.1.0~alpha3 Release: 1%{?dist} Summary: Windows Hello equivalent for Linux — biometric PAM authentication License: GPL-3.0-only URL: https://github.com/giacomofurlan/linux-hello Source0: %{name}-%{version}.tar.gz BuildRequires: rust >= 1.97 BuildRequires: cargo >= 1.97 BuildRequires: cmake BuildRequires: clang BuildRequires: pkgconfig BuildRequires: pkgconfig(Qt6Core) BuildRequires: pkgconfig(Qt6Qml) BuildRequires: pkgconfig(Qt6Quick) BuildRequires: pkgconfig(Qt6Svg) BuildRequires: pkgconfig(tss2-esys) BuildRequires: pkgconfig(opencv4) BuildRequires: pkgconfig(pam) BuildRequires: pkgconfig(dbus-1) BuildRequires: pkgconfig(sqlite3) BuildRequires: checkpolicy BuildRequires: policycoreutils Requires: qt6-qtbase Requires: qt6-qtdeclarative Requires: tpm2-tss Requires: pam Requires: dbus Requires(pre): shadow-utils # Declare that this package creates the linux-hello user/group (done in %pre). # RPM's scriptlet auto-detection does not reliably pick up the getent||useradd # pattern, so we declare the virtual provides explicitly. Provides: user(linux-hello) Provides: group(linux-hello) Requires(post): systemd Requires(post): curl Requires(preun): systemd Requires(postun): systemd Recommends: tpm2-abrmd Recommends: fprintd Suggests: pamtester %description linux-hello provides PAM-integrated biometric and hardware-token authentication for Linux, analogous to Windows Hello. It supports face recognition (IR and RGB), fingerprint (via fprintd), FIDO2/WebAuthn hardware keys, PIN, and TOTP. The trust policy is TPM-sealed and configurable per PAM service. %prep %autosetup %build export CARGO_PROFILE_RELEASE_CODEGEN_UNITS=$(nproc) cargo build --release --workspace --exclude linux-hello-pam cargo build --release -p linux-hello-pam %install install -Dm755 target/release/linux-hello-daemon %{buildroot}%{_bindir}/linux-hello-daemon install -Dm755 target/release/linux-hello-notify %{buildroot}%{_bindir}/linux-hello-notify install -Dm755 target/release/linux-hello-enroll %{buildroot}%{_bindir}/linux-hello-enroll install -Dm755 target/release/linux-hello-admin %{buildroot}%{_bindir}/linux-hello-admin install -Dm755 target/release/linux-hello-overlay %{buildroot}%{_bindir}/linux-hello-overlay install -Dm755 target/release/linux-hello-greetd %{buildroot}%{_bindir}/linux-hello-greetd install -Dm755 target/release/linux-hello-sddm-helper %{buildroot}%{_libdir}/linux-hello/linux-hello-sddm-helper install -Dm644 target/release/libpam_linux_hello.so %{buildroot}%{_libdir}/security/pam_linux_hello.so install -Dm644 config/pam/linux-hello \ %{buildroot}%{_sysconfdir}/pam.d/linux-hello install -Dm644 config/systemd/linux-hello.service \ %{buildroot}%{_unitdir}/linux-hello.service install -Dm644 config/systemd/90-linux-hello.preset \ %{buildroot}%{_presetdir}/90-linux-hello.preset install -Dm644 config/systemd/linux-hello-sddm-helper.service \ %{buildroot}%{_unitdir}/linux-hello-sddm-helper.service install -Dm644 config/systemd/linux-hello-reseal.service \ %{buildroot}%{_unitdir}/linux-hello-reseal.service install -Dm644 config/systemd/linux-hello-overlay.service \ %{buildroot}%{_userunitdir}/linux-hello-overlay.service install -Dm644 config/systemd/linux-hello-notify.service \ %{buildroot}%{_userunitdir}/linux-hello-notify.service install -Dm644 config/dbus/linux-hello.conf \ %{buildroot}%{_datadir}/dbus-1/system.d/linux-hello.conf install -Dm644 polkit/name.giacomofurlan.linux_hello.policy \ %{buildroot}%{_datadir}/polkit-1/actions/name.giacomofurlan.linux_hello.policy install -Dm755 config/kernel-install/90-linux-hello-reseal.install \ %{buildroot}%{_prefix}/lib/kernel/install.d/90-linux-hello-reseal.install install -Dm644 config/applications/linux-hello-enroll.desktop \ %{buildroot}%{_datadir}/applications/linux-hello-enroll.desktop install -Dm644 config/applications/linux-hello-admin.desktop \ %{buildroot}%{_datadir}/applications/linux-hello-admin.desktop install -Dm644 assets/icons/linux-hello.svg \ %{buildroot}%{_datadir}/icons/hicolor/scalable/apps/linux-hello.svg install -Dm644 assets/icons/linux-hello-256.png \ %{buildroot}%{_datadir}/icons/hicolor/256x256/apps/linux-hello.png install -Dm644 assets/icons/linux-hello-48.png \ %{buildroot}%{_datadir}/icons/hicolor/48x48/apps/linux-hello.png install -dm755 %{buildroot}%{_sysconfdir}/linux-hello install -dm755 %{buildroot}%{_sharedstatedir}/linux-hello install -Dm755 packaging/download-models.sh %{buildroot}%{_datadir}/linux-hello/download-models.sh install -Dm644 packaging/models/checksums.sha256 %{buildroot}%{_datadir}/linux-hello/models/checksums.sha256 install -dm755 %{buildroot}%{_datadir}/linux-hello/models install -Dm644 config/udev/70-linux-hello.rules \ %{buildroot}%{_udevrulesdir}/70-linux-hello.rules # SELinux policy module — subshell keeps the cd from affecting subsequent paths. (cd config/selinux && \ checkmodule -M -m -o linux_hello.mod linux_hello.te && \ semodule_package -o linux_hello.pp -m linux_hello.mod -f linux_hello.fc) install -Dm644 config/selinux/linux_hello.pp \ %{buildroot}%{_datadir}/linux-hello/selinux/linux_hello.pp install -Dm644 config/selinux/linux_hello.te \ %{buildroot}%{_datadir}/linux-hello/selinux/linux_hello.te install -Dm644 config/selinux/linux_hello.fc \ %{buildroot}%{_datadir}/linux-hello/selinux/linux_hello.fc install -dm755 %{buildroot}%{_datadir}/sddm/themes cp -r config/sddm/theme/linux-hello \ %{buildroot}%{_datadir}/sddm/themes/linux-hello cp -r config/sddm/theme/linux-hello-xmb \ %{buildroot}%{_datadir}/sddm/themes/linux-hello-xmb install -dm755 %{buildroot}%{_datadir}/plasma/look-and-feel cp -r config/kscreenlocker/theme/linux-hello \ %{buildroot}%{_datadir}/plasma/look-and-feel/linux-hello cp -r config/kscreenlocker/theme/linux-hello-xmb \ %{buildroot}%{_datadir}/plasma/look-and-feel/linux-hello-xmb %pre # Stop the daemon before upgrade so the binary can be replaced. if [ $1 -ge 2 ] && [ -d /run/systemd/system ]; then systemctl is-active --quiet linux-hello.service && \ systemctl stop linux-hello.service || : fi getent group linux-hello >/dev/null || groupadd --system linux-hello getent passwd linux-hello >/dev/null || \ useradd --system --gid linux-hello \ --home-dir %{_sharedstatedir}/linux-hello \ --shell /sbin/nologin \ --comment "Linux Hello daemon" \ linux-hello # Add to tss group for TPM access and video group for face recognition. getent group tss >/dev/null && usermod -aG tss linux-hello || : getent group video >/dev/null && usermod -aG video linux-hello || : %post %systemd_post linux-hello.service linux-hello-sddm-helper.service linux-hello-reseal.service install -dm700 -o linux-hello -g linux-hello %{_sharedstatedir}/linux-hello # On upgrade from v1: remove the old SCRFD-500M model (replaced by det_10g.onnx). if [ $1 -ge 2 ]; then rm -f %{_datadir}/linux-hello/models/scrfd_500m.onnx fi /usr/share/linux-hello/download-models.sh || \ echo "WARNING: model download failed; run sudo /usr/share/linux-hello/download-models.sh manually" # Install SELinux policy so SDDM's PAM helper can connect to the PAM socket. if [ -x /usr/sbin/semodule ]; then semodule -i %{_datadir}/linux-hello/selinux/linux_hello.pp 2>/dev/null || : restorecon -Rv /run/linux-hello 2>/dev/null || : fi %preun %systemd_preun linux-hello.service linux-hello-sddm-helper.service linux-hello-reseal.service if [ $1 -eq 0 ]; then rm -f %{_datadir}/linux-hello/models/det_10g.onnx \ %{_datadir}/linux-hello/models/scrfd_500m.onnx \ %{_datadir}/linux-hello/models/arcface_r50.onnx \ %{_datadir}/linux-hello/models/minifasnet_v2.onnx fi %postun %systemd_postun_with_restart linux-hello.service linux-hello-sddm-helper.service linux-hello-reseal.service # Remove SELinux policy on uninstall. if [ $1 -eq 0 ] && [ -x /usr/sbin/semodule ]; then semodule -r linux_hello 2>/dev/null || : fi %files %license LICENSE %doc README.md %{_bindir}/linux-hello-daemon %{_bindir}/linux-hello-notify %{_bindir}/linux-hello-enroll %{_bindir}/linux-hello-admin %{_bindir}/linux-hello-overlay %{_bindir}/linux-hello-greetd %{_libdir}/linux-hello/linux-hello-sddm-helper %{_libdir}/security/pam_linux_hello.so %config(noreplace) %{_sysconfdir}/pam.d/linux-hello %{_unitdir}/linux-hello.service %{_presetdir}/90-linux-hello.preset %{_unitdir}/linux-hello-sddm-helper.service %{_unitdir}/linux-hello-reseal.service %{_userunitdir}/linux-hello-overlay.service %{_userunitdir}/linux-hello-notify.service %{_datadir}/dbus-1/system.d/linux-hello.conf %{_datadir}/polkit-1/actions/name.giacomofurlan.linux_hello.policy %{_prefix}/lib/kernel/install.d/90-linux-hello-reseal.install %{_datadir}/applications/linux-hello-enroll.desktop %{_datadir}/applications/linux-hello-admin.desktop %{_datadir}/icons/hicolor/scalable/apps/linux-hello.svg %{_datadir}/icons/hicolor/256x256/apps/linux-hello.png %{_datadir}/icons/hicolor/48x48/apps/linux-hello.png %dir %{_sysconfdir}/linux-hello %attr(700,linux-hello,linux-hello) %dir %{_sharedstatedir}/linux-hello %{_datadir}/sddm/themes/linux-hello %{_datadir}/sddm/themes/linux-hello-xmb %{_datadir}/plasma/look-and-feel/linux-hello %{_datadir}/plasma/look-and-feel/linux-hello-xmb %{_datadir}/linux-hello/download-models.sh %dir %{_datadir}/linux-hello/models %{_datadir}/linux-hello/models/checksums.sha256 %dir %{_datadir}/linux-hello/selinux %{_datadir}/linux-hello/selinux/linux_hello.pp %{_datadir}/linux-hello/selinux/linux_hello.te %{_datadir}/linux-hello/selinux/linux_hello.fc %{_udevrulesdir}/70-linux-hello.rules %ghost %{_datadir}/linux-hello/models/det_10g.onnx %ghost %{_datadir}/linux-hello/models/arcface_r50.onnx %ghost %{_datadir}/linux-hello/models/minifasnet_v2.onnx %changelog * Mon Sep 28 2026 Giacomo 'Mr. Wolf' Furlan - 0.1.0~alpha3-1 - Explicit consent gate before biometric auth in graphical non-DM sessions: a blocking overlay prompt appears when an app requests biometric authentication; auth is denied on timeout. - `polkit-1` PAM config; polkit is excluded from the overlay consent gate to avoid deadlocks. - GNOME Keyring unlock moved to `pam_sm_open_session` (was a racy daemon-side fire-and-forget); dropped legacy `kwalletd5` socket path and fixed KDE session detection to use config files. - Consent gate is now blocking: auth is denied on timeout; overlay is required for graphical sessions. - Overlay and notify systemd units enabled globally via a systemd preset (no manual `systemctl enable` needed after install). - Slint gettext integration wired in the overlay; all user-facing strings go through `@tr(…)` / `tr!()`, with translations for all supported locales. - `linux-hello-enroll` polls `GetAvailableAuthenticators` on-demand while its window is open; removed the daemon-side 2 s availability poll that hammered the IR/RGB camera even when no client was listening. - `kwalletd` support has dropped, as apparently there is no way to programmatically unlock the wallet by design (previously the system tried to provide the password to the socket, based off Plasma5 version of the software, but it's not compatible with Plasma6) - `FaceProvider::is_available()` scanned only fixed `/dev/video0`–`3`; now enumerates cameras via sysfs, matching the face pipeline, so it survives `/dev` node renumbering (replug, suspend/resume, extra webcams). - Overlay initial visibility: surface now starts hidden via `run_event_loop()` + `ui.hide()`, shows on auth events, and shrinks to 1×1 px on hide to avoid a KWin null-buffer remap bug; Ctrl+C cancels auth. - Layer-shell surface hidden via null buffer when idle; pointer input wired to prevent input passthrough while visible. - Consent gate skips the overlay popup when `PAM_TTY` is a real terminal (`pts`/`tty`) or when the session is not graphical. - `is_graphical_session()` removed from `needs_consent`: polkit-kde strips session environment variables, making the check unreliable. - `pam_sm_open_session` skips PAM conversation for graphical non-DM consent contexts. - PAM config paths: module name no longer hardcodes `secdir`; fixed by using the bare module name. - Overlay systemd service install path corrected to `user/` (was `system/`); user preset split from system preset. - Bumped `ratatui` to 0.30 and `crossterm` to 0.29 to remove the transitive unsound dependency on `lru 0.12.5` (RUSTSEC-2026-0002, RUSTSEC-2026-0253). _Initial public alpha._ [Unreleased]: https://github.com/giacomofurlan/linux-hello/compare/v0.1.0-alpha3...HEAD [0.1.0-alpha3]: https://github.com/giacomofurlan/linux-hello/compare/v0.1.0-alpha2...v0.1.0-alpha3 [0.1.0-alpha2]: https://github.com/giacomofurlan/linux-hello/releases/tag/v0.1.0-alpha2 * Mon Jul 27 2026 Giacomo Furlan - 0.1.0-1 - Initial RPM packaging.