diff --git a/CHANGELOG.md b/CHANGELOG.md index b33a7a8..ffdb680 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -25,6 +25,13 @@ one per merged pull request. - **docs: Shorter README, with a Steam Machine section** - How it works moved to `TECHNICAL.md`, problems to `TROUBLESHOOTING.md`; the README links to them and to the files it mentions. +- **feat: No more KDE wallet password prompts in single user mode** + - Uses Valve's empty, password-less wallet, like SteamOS; apps such as + Brave no longer ask for the wallet password after autologin. + - Your own wallet is moved to `kdewallet.kwl.bak-steamify` and comes back, + unchanged, when single user mode is off; the single user wallet is kept + and reused next time. + - Moved from the SteamOS theme, where it only helped without any wallet. - **docs: LICENSE.md** with the MIT license the README already named. - **chore: No more `setup-gamescope-boot.sh` release asset** - Only `steamify.sh` is published; the old name from before 0.9.0 is gone. diff --git a/README.md b/README.md index f28c563..a312908 100644 --- a/README.md +++ b/README.md @@ -21,8 +21,9 @@ Steam Machine. **Add to Steam** in right-click menus ([details](TECHNICAL.md#steamos-desktop-look)). 3. **Steam Deck/Machine icons** - Steam Deck button icons in gaming mode. -4. **Single user mode** - like SteamOS: never a login or lock screen. Typing a - password with a controller is no fun +4. **Single user mode** - like SteamOS: never a login or lock screen, and no + KDE wallet password prompts (e.g. from Brave). Typing a password with a + controller is no fun ([details](TECHNICAL.md#single-user-mode-sddm-no-locking)). 5. **Steamify shortcut** - an icon on the desktop and in the launcher that opens the newest Steamify, so you don't need the install command again. diff --git a/TECHNICAL.md b/TECHNICAL.md index 3034313..918ac16 100644 --- a/TECHNICAL.md +++ b/TECHNICAL.md @@ -32,6 +32,17 @@ the Session dropdown with Log Out. (Restricting `action/logout` would also hide Restart and Shut Down.) Turning it off restores all of that and moves the conversion back to plasma-login-manager. +**KDE wallet.** KDE normally unlocks your wallet with the password you log in +with; with autologin nobody types it, so apps that keep passwords in it (Brave, +for example) ask for the wallet password. Single user mode does what SteamOS +does: it uses Valve's empty wallet without a password (from +`steamdeck-kde-presets`, checksum verified). Your own wallet in +`~/.local/share/kwalletd/` is moved to `kdewallet.kwl.bak-steamify` (and +`.salt`). Turning single user mode off puts it back, unchanged; the single +user wallet, with anything saved in it meanwhile, is kept as +`kdewallet.kwl.steamify-single-user` and used again the next time it's on. +Passwords aren't shared between the two wallets. + **SDDM** is what SteamOS uses, and CachyOS's `steam-set-session` supports it directly: it writes `/etc/sddm.conf.d/zz-steamos-autologin.conf`, which SDDM honours. The script installs and enables `sddm` (active from the next boot), @@ -123,9 +134,7 @@ taken from the newest `steamdeck-kde-presets` on Valve's SteamOS mirror - **Nested Desktop**: add it to Steam from the launcher, then start it in gaming mode for a Plasma desktop inside gaming mode; - the SteamOS **Return to Gaming Mode** icon (Steam logo with a return arrow); -- a window rule that keeps the **Steam keyboard** above other windows; -- an empty, password-less **KWallet**, only if you don't have a wallet yet, - so nothing asks for a wallet password after autologin. +- a window rule that keeps the **Steam keyboard** above other windows. Turning it off restores your previous look and panel layout, and removes `cachyos-vapor` again if the wizard installed it (and nothing else, like `cachyos-handheld`, needs it). diff --git a/lib/single-user.sh b/lib/single-user.sh index 7be65db..878e839 100644 --- a/lib/single-user.sh +++ b/lib/single-user.sh @@ -9,6 +9,78 @@ single_status() { [[ "$(kreadconfig6 --file kdeglobals --group "KDE Action Restrictions" --key action/lock_screen)" == false ]] } +WALLET_DIR="${XDG_DATA_HOME:-$HOME/.local/share}/kwalletd" +# The user's own wallet while single user mode is on, and ours after. +WALLET_BACKUP=".bak-steamify" +WALLET_OURS=".steamify-single-user" + +stop_kwallet() { + # The wallet daemon keeps the file open and would write it back. + local d + for d in kwalletd6 ksecretd; do + pkill -u "$USER" -x "$d" 2>/dev/null && sleep 1 + done + return 0 +} + +single_wallet_enable() { + # Like SteamOS: an empty, password-less wallet (Valve's own file), so + # nothing asks for a wallet password (e.g. Brave at start): with + # autologin nobody typed the login password that unlocks the usual one. + # The user's wallet is moved aside and comes back when this is off. The + # wallet from an earlier time in single user mode is reused, with + # whatever was saved in it then. + local tmp f + if [[ -f "$WALLET_DIR/kdewallet.kwl$WALLET_OURS" ]]; then + stop_kwallet + for f in kdewallet.kwl kdewallet.salt; do + [[ -f "$WALLET_DIR/$f" && ! -e "$WALLET_DIR/$f$WALLET_BACKUP" ]] && + mv "$WALLET_DIR/$f" "$WALLET_DIR/$f$WALLET_BACKUP" + [[ -f "$WALLET_DIR/$f$WALLET_OURS" ]] && mv -f "$WALLET_DIR/$f$WALLET_OURS" "$WALLET_DIR/$f" + done + kset single kwalletrc Wallet "First Use" false + ok "Single user mode's wallet (no password) is back; your own is kept as kdewallet.kwl$WALLET_BACKUP." + return 0 + fi + tmp="$(mktemp -d)" + if ! fetch_valve_presets "$tmp"; then + rm -rf "$tmp" + warn "Couldn't get Valve's empty wallet; apps may still ask for the wallet password." + return 0 + fi + if [[ -f "$WALLET_DIR/kdewallet.kwl" ]] && + cmp -s "$WALLET_DIR/kdewallet.kwl" "$tmp/usr/share/kwalletd/kdewallet.kwl"; then + rm -rf "$tmp" + return 0 + fi + stop_kwallet + mkdir -p "$WALLET_DIR" + for f in kdewallet.kwl kdewallet.salt; do + # Never overwrite an earlier backup: that one is the user's. + [[ -f "$WALLET_DIR/$f" && ! -e "$WALLET_DIR/$f$WALLET_BACKUP" ]] && + mv "$WALLET_DIR/$f" "$WALLET_DIR/$f$WALLET_BACKUP" + install -m 600 "$tmp/usr/share/kwalletd/$f" "$WALLET_DIR/$f" + done + rm -rf "$tmp" + kset single kwalletrc Wallet "First Use" false + [[ -f "$WALLET_DIR/kdewallet.kwl$WALLET_BACKUP" ]] && + info "Your wallet is kept as $WALLET_DIR/kdewallet.kwl$WALLET_BACKUP and comes back when single user mode is off." + ok "Empty wallet without a password: apps no longer ask for the wallet password." +} + +single_wallet_disable() { + # The user's wallet back; ours (maybe with passwords saved since) is + # kept next to it. + [[ -f "$WALLET_DIR/kdewallet.kwl$WALLET_BACKUP" ]] || return 0 + stop_kwallet + local f + for f in kdewallet.kwl kdewallet.salt; do + [[ -f "$WALLET_DIR/$f" ]] && mv -f "$WALLET_DIR/$f" "$WALLET_DIR/$f$WALLET_OURS" + [[ -f "$WALLET_DIR/$f$WALLET_BACKUP" ]] && mv "$WALLET_DIR/$f$WALLET_BACKUP" "$WALLET_DIR/$f" + done + ok "Your own wallet is back (the empty one is kept as kdewallet.kwl$WALLET_OURS)." +} + single_launcher() { # Launcher: only Sleep / Restart / Shut Down, no Session dropdown (where # Log Out lives). Restricting action/logout instead would also hide @@ -42,6 +114,7 @@ single_enable() { single_launcher restart_plasmashell_if_stopped + single_wallet_enable ok "Single user: no lock screen, user switching or log out." } @@ -70,5 +143,6 @@ single_disable() { done fi restart_plasmashell_if_stopped + single_wallet_disable ok "KDE's normal lock screen and user switching are back." } diff --git a/lib/steamos-extras.sh b/lib/steamos-extras.sh index 5e75205..ca40c3e 100644 --- a/lib/steamos-extras.sh +++ b/lib/steamos-extras.sh @@ -3,7 +3,7 @@ # newest Valve steamdeck-kde-presets package: "Add to Steam" (file # right-click menu and launcher), Nested Desktop (Plasma as a game inside # gaming mode), the "Return to Gaming Mode" icon, the Steam Keyboard window -# rule and an empty KWallet. Part of the SteamOS theme component +# rule. Part of the SteamOS theme component # (lib/vapor-theme.sh). System files go to /usr/local (nothing # package-owned); per-user settings go through the undo journal. # Sourced by steamify.sh; not meant to be run on its own. @@ -75,15 +75,6 @@ extras_enable() { sudo cp -r "$src/share/applications/steam/holo-nested-desktop" "$NESTED_DIR" sudo sed -i "s|/usr/share/applications/steam/holo-nested-desktop|$NESTED_DIR|" "$NESTED_DIR/holo-nested-desktop.desktop" - # An empty, password-less wallet (Valve's), so nothing asks for a wallet - # password: with autologin nobody typed one to unlock it. Only when the - # user has no wallet yet; an existing one is never touched. - local wallet="${XDG_DATA_HOME:-$HOME/.local/share}/kwalletd" - if [[ ! -f "$wallet/kdewallet.kwl" ]]; then - mkdir -p "$wallet" - install -m 600 "$src/share/kwalletd/kdewallet.kwl" "$src/share/kwalletd/kdewallet.salt" "$wallet/" - kset theme kwalletrc Wallet "First Use" false - fi rm -rf "$tmp_dir" sudo gtk-update-icon-cache -q -f -t /usr/local/share/icons/hicolor 2>/dev/null || true @@ -122,7 +113,6 @@ extras_disable() { for pkg in kdialog zstd curl; do [[ -n "$(state_get theme "installed_$pkg")" ]] && sudo pacman -R --noconfirm "$pkg" >/dev/null 2>&1 done - # The keyboard rule and kwalletrc are reverted by the theme's journal. - # The wallet itself stays: secrets may have been saved in it since. + # The keyboard rule is reverted by the theme's journal. return 0 }