Add opt-in Plasma fingerprint workaround
This commit is contained in:
@@ -0,0 +1,60 @@
|
||||
# Plasma fingerprint workaround
|
||||
|
||||
This is an experimental and unaudited replacement for Fedora's KScreenLocker
|
||||
package. It changes security-sensitive session-locking and authentication code.
|
||||
Review the patches and build the package yourself if you do not trust the
|
||||
provided binary.
|
||||
|
||||
Installing `plasma-fingerprint-workaround` does not enable the workaround or
|
||||
modify KScreenLocker. The controller only acts when explicitly asked:
|
||||
|
||||
```bash
|
||||
sudo plasma-fingerprint-workaround enable
|
||||
plasma-fingerprint-workaround status
|
||||
sudo plasma-fingerprint-workaround disable
|
||||
```
|
||||
|
||||
The default payload is kept outside the DNF repository. The controller checks
|
||||
its pinned SHA-256 digest, RPM integrity, package name, architecture, and
|
||||
workaround metadata before asking DNF to install it. Disabling the workaround
|
||||
restores the current KScreenLocker package from Fedora's `fedora` or `updates`
|
||||
repository.
|
||||
|
||||
The provided build currently supports Fedora 44 on x86_64 and is based on
|
||||
`kscreenlocker-6.7.4-1.fc44`. A different base version is rejected by default.
|
||||
To intentionally install the older provided build after a KScreenLocker update:
|
||||
|
||||
```bash
|
||||
sudo plasma-fingerprint-workaround enable --force
|
||||
```
|
||||
|
||||
## Locally built package
|
||||
|
||||
Build dependencies can be installed and the package built with:
|
||||
|
||||
```bash
|
||||
sudo dnf5 builddep plasma-fingerprint-workaround/kscreenlocker/kscreenlocker.spec
|
||||
./scripts/build-patched-kscreenlocker-rpm
|
||||
```
|
||||
|
||||
Install the resulting package directly through the controller:
|
||||
|
||||
```bash
|
||||
sudo plasma-fingerprint-workaround enable \
|
||||
--rpm rpmbuild/RPMS/x86_64/kscreenlocker-6.7.4-1.fc44.ajp5.x86_64.rpm
|
||||
```
|
||||
|
||||
For another upstream version, supply its version, Fedora base release, and
|
||||
source archive checksum. The patches must still apply and compile cleanly.
|
||||
|
||||
```bash
|
||||
KSCREENLOCKER_VERSION=6.7.5 \
|
||||
KSCREENLOCKER_BASE_RELEASE=1 \
|
||||
KSCREENLOCKER_SOURCE_SHA256=SHA256 \
|
||||
./scripts/build-patched-kscreenlocker-rpm
|
||||
```
|
||||
|
||||
A locally built package based on a different installed version requires
|
||||
`--force`. This flag permits the version mismatch and allows DNF to downgrade;
|
||||
it does not bypass the package identity, architecture, integrity, or workaround
|
||||
metadata checks.
|
||||
Reference in New Issue
Block a user