Files
fedora-tools/plasma-fingerprint-workaround/README.md
T

2.1 KiB

Plasma fingerprint workaround

This is an experimental and unaudited replacement for Fedora's KScreenLocker package. It changes security-sensitive session-locking and authentication code. Review the patches and build the package yourself if you do not trust the provided binary.

Installing plasma-fingerprint-workaround does not enable the workaround or modify KScreenLocker. The controller only acts when explicitly asked:

sudo plasma-fingerprint-workaround enable
plasma-fingerprint-workaround status
sudo plasma-fingerprint-workaround disable

The default payload is kept outside the DNF repository. The controller checks its pinned SHA-256 digest, RPM integrity, package name, architecture, and workaround metadata before asking DNF to install it. Disabling the workaround restores the current KScreenLocker package from Fedora's fedora or updates repository.

The provided build currently supports Fedora 44 on x86_64 and is based on kscreenlocker-6.7.4-1.fc44. A different base version is rejected by default. To intentionally install the older provided build after a KScreenLocker update:

sudo plasma-fingerprint-workaround enable --force

Locally built package

Build dependencies can be installed and the package built with:

sudo dnf5 builddep plasma-fingerprint-workaround/kscreenlocker/kscreenlocker.spec
./scripts/build-patched-kscreenlocker-rpm

Install the resulting package directly through the controller:

sudo plasma-fingerprint-workaround enable \
  --rpm rpmbuild/RPMS/x86_64/kscreenlocker-6.7.4-1.fc44.ajp5.x86_64.rpm

For another upstream version, supply its version, Fedora base release, and source archive checksum. The patches must still apply and compile cleanly.

KSCREENLOCKER_VERSION=6.7.5 \
KSCREENLOCKER_BASE_RELEASE=1 \
KSCREENLOCKER_SOURCE_SHA256=SHA256 \
  ./scripts/build-patched-kscreenlocker-rpm

A locally built package based on a different installed version requires --force. This flag permits the version mismatch and allows DNF to downgrade; it does not bypass the package identity, architecture, integrity, or workaround metadata checks.