feat: No more KDE wallet password prompts in single user mode

Valve's empty, password-less wallet, like SteamOS. The user's wallet is
moved aside and restored when single user mode is off; the single user
wallet is kept and reused next time.
This commit is contained in:
theupriser committed 2026-09-25 08:27:50 +02:00
1 parent 3e3ededc62
commit ebfffe81e7
5 files changed
+98 -17

No files matched your search

+7
View File
@@ -25,6 +25,13 @@ one per merged pull request.
- **docs: Shorter README, with a Steam Machine section**
- How it works moved to `TECHNICAL.md`, problems to `TROUBLESHOOTING.md`;
the README links to them and to the files it mentions.
- **feat: No more KDE wallet password prompts in single user mode**
- Uses Valve's empty, password-less wallet, like SteamOS; apps such as
Brave no longer ask for the wallet password after autologin.
- Your own wallet is moved to `kdewallet.kwl.bak-steamify` and comes back,
unchanged, when single user mode is off; the single user wallet is kept
and reused next time.
- Moved from the SteamOS theme, where it only helped without any wallet.
- **docs: LICENSE.md** with the MIT license the README already named.
- **chore: No more `setup-gamescope-boot.sh` release asset**
- Only `steamify.sh` is published; the old name from before 0.9.0 is gone.
+3 -2
View File
@@ -21,8 +21,9 @@ Steam Machine.
**Add to Steam** in right-click menus
([details](TECHNICAL.md#steamos-desktop-look)).
3. **Steam Deck/Machine icons** - Steam Deck button icons in gaming mode.
4. **Single user mode** - like SteamOS: never a login or lock screen. Typing a
password with a controller is no fun
4. **Single user mode** - like SteamOS: never a login or lock screen, and no
KDE wallet password prompts (e.g. from Brave). Typing a password with a
controller is no fun
([details](TECHNICAL.md#single-user-mode-sddm-no-locking)).
5. **Steamify shortcut** - an icon on the desktop and in the launcher that
opens the newest Steamify, so you don't need the install command again.
+12 -3
View File
@@ -32,6 +32,17 @@ the Session dropdown with Log Out. (Restricting `action/logout` would also
hide Restart and Shut Down.) Turning it off restores all of that and moves
the conversion back to plasma-login-manager.
**KDE wallet.** KDE normally unlocks your wallet with the password you log in
with; with autologin nobody types it, so apps that keep passwords in it (Brave,
for example) ask for the wallet password. Single user mode does what SteamOS
does: it uses Valve's empty wallet without a password (from
`steamdeck-kde-presets`, checksum verified). Your own wallet in
`~/.local/share/kwalletd/` is moved to `kdewallet.kwl.bak-steamify` (and
`.salt`). Turning single user mode off puts it back, unchanged; the single
user wallet, with anything saved in it meanwhile, is kept as
`kdewallet.kwl.steamify-single-user` and used again the next time it's on.
Passwords aren't shared between the two wallets.
**SDDM** is what SteamOS uses, and CachyOS's `steam-set-session` supports it
directly: it writes `/etc/sddm.conf.d/zz-steamos-autologin.conf`, which SDDM
honours. The script installs and enables `sddm` (active from the next boot),
@@ -123,9 +134,7 @@ taken from the newest `steamdeck-kde-presets` on Valve's SteamOS mirror
- **Nested Desktop**: add it to Steam from the launcher, then start it in
gaming mode for a Plasma desktop inside gaming mode;
- the SteamOS **Return to Gaming Mode** icon (Steam logo with a return arrow);
- a window rule that keeps the **Steam keyboard** above other windows;
- an empty, password-less **KWallet**, only if you don't have a wallet yet,
so nothing asks for a wallet password after autologin.
- a window rule that keeps the **Steam keyboard** above other windows.
Turning it off restores your previous look and panel layout, and removes `cachyos-vapor` again
if the wizard installed it (and nothing else, like `cachyos-handheld`, needs it).
+74
View File
@@ -9,6 +9,78 @@ single_status() {
[[ "$(kreadconfig6 --file kdeglobals --group "KDE Action Restrictions" --key action/lock_screen)" == false ]]
}
WALLET_DIR="${XDG_DATA_HOME:-$HOME/.local/share}/kwalletd"
# The user's own wallet while single user mode is on, and ours after.
WALLET_BACKUP=".bak-steamify"
WALLET_OURS=".steamify-single-user"
stop_kwallet() {
# The wallet daemon keeps the file open and would write it back.
local d
for d in kwalletd6 ksecretd; do
pkill -u "$USER" -x "$d" 2>/dev/null && sleep 1
done
return 0
}
single_wallet_enable() {
# Like SteamOS: an empty, password-less wallet (Valve's own file), so
# nothing asks for a wallet password (e.g. Brave at start): with
# autologin nobody typed the login password that unlocks the usual one.
# The user's wallet is moved aside and comes back when this is off. The
# wallet from an earlier time in single user mode is reused, with
# whatever was saved in it then.
local tmp f
if [[ -f "$WALLET_DIR/kdewallet.kwl$WALLET_OURS" ]]; then
stop_kwallet
for f in kdewallet.kwl kdewallet.salt; do
[[ -f "$WALLET_DIR/$f" && ! -e "$WALLET_DIR/$f$WALLET_BACKUP" ]] &&
mv "$WALLET_DIR/$f" "$WALLET_DIR/$f$WALLET_BACKUP"
[[ -f "$WALLET_DIR/$f$WALLET_OURS" ]] && mv -f "$WALLET_DIR/$f$WALLET_OURS" "$WALLET_DIR/$f"
done
kset single kwalletrc Wallet "First Use" false
ok "Single user mode's wallet (no password) is back; your own is kept as kdewallet.kwl$WALLET_BACKUP."
return 0
fi
tmp="$(mktemp -d)"
if ! fetch_valve_presets "$tmp"; then
rm -rf "$tmp"
warn "Couldn't get Valve's empty wallet; apps may still ask for the wallet password."
return 0
fi
if [[ -f "$WALLET_DIR/kdewallet.kwl" ]] &&
cmp -s "$WALLET_DIR/kdewallet.kwl" "$tmp/usr/share/kwalletd/kdewallet.kwl"; then
rm -rf "$tmp"
return 0
fi
stop_kwallet
mkdir -p "$WALLET_DIR"
for f in kdewallet.kwl kdewallet.salt; do
# Never overwrite an earlier backup: that one is the user's.
[[ -f "$WALLET_DIR/$f" && ! -e "$WALLET_DIR/$f$WALLET_BACKUP" ]] &&
mv "$WALLET_DIR/$f" "$WALLET_DIR/$f$WALLET_BACKUP"
install -m 600 "$tmp/usr/share/kwalletd/$f" "$WALLET_DIR/$f"
done
rm -rf "$tmp"
kset single kwalletrc Wallet "First Use" false
[[ -f "$WALLET_DIR/kdewallet.kwl$WALLET_BACKUP" ]] &&
info "Your wallet is kept as $WALLET_DIR/kdewallet.kwl$WALLET_BACKUP and comes back when single user mode is off."
ok "Empty wallet without a password: apps no longer ask for the wallet password."
}
single_wallet_disable() {
# The user's wallet back; ours (maybe with passwords saved since) is
# kept next to it.
[[ -f "$WALLET_DIR/kdewallet.kwl$WALLET_BACKUP" ]] || return 0
stop_kwallet
local f
for f in kdewallet.kwl kdewallet.salt; do
[[ -f "$WALLET_DIR/$f" ]] && mv -f "$WALLET_DIR/$f" "$WALLET_DIR/$f$WALLET_OURS"
[[ -f "$WALLET_DIR/$f$WALLET_BACKUP" ]] && mv "$WALLET_DIR/$f$WALLET_BACKUP" "$WALLET_DIR/$f"
done
ok "Your own wallet is back (the empty one is kept as kdewallet.kwl$WALLET_OURS)."
}
single_launcher() {
# Launcher: only Sleep / Restart / Shut Down, no Session dropdown (where
# Log Out lives). Restricting action/logout instead would also hide
@@ -42,6 +114,7 @@ single_enable() {
single_launcher
restart_plasmashell_if_stopped
single_wallet_enable
ok "Single user: no lock screen, user switching or log out."
}
@@ -70,5 +143,6 @@ single_disable() {
done
fi
restart_plasmashell_if_stopped
single_wallet_disable
ok "KDE's normal lock screen and user switching are back."
}
+2 -12
View File
@@ -3,7 +3,7 @@
# newest Valve steamdeck-kde-presets package: "Add to Steam" (file
# right-click menu and launcher), Nested Desktop (Plasma as a game inside
# gaming mode), the "Return to Gaming Mode" icon, the Steam Keyboard window
# rule and an empty KWallet. Part of the SteamOS theme component
# rule. Part of the SteamOS theme component
# (lib/vapor-theme.sh). System files go to /usr/local (nothing
# package-owned); per-user settings go through the undo journal.
# Sourced by steamify.sh; not meant to be run on its own.
@@ -75,15 +75,6 @@ extras_enable() {
sudo cp -r "$src/share/applications/steam/holo-nested-desktop" "$NESTED_DIR"
sudo sed -i "s|/usr/share/applications/steam/holo-nested-desktop|$NESTED_DIR|" "$NESTED_DIR/holo-nested-desktop.desktop"
# An empty, password-less wallet (Valve's), so nothing asks for a wallet
# password: with autologin nobody typed one to unlock it. Only when the
# user has no wallet yet; an existing one is never touched.
local wallet="${XDG_DATA_HOME:-$HOME/.local/share}/kwalletd"
if [[ ! -f "$wallet/kdewallet.kwl" ]]; then
mkdir -p "$wallet"
install -m 600 "$src/share/kwalletd/kdewallet.kwl" "$src/share/kwalletd/kdewallet.salt" "$wallet/"
kset theme kwalletrc Wallet "First Use" false
fi
rm -rf "$tmp_dir"
sudo gtk-update-icon-cache -q -f -t /usr/local/share/icons/hicolor 2>/dev/null || true
@@ -122,7 +113,6 @@ extras_disable() {
for pkg in kdialog zstd curl; do
[[ -n "$(state_get theme "installed_$pkg")" ]] && sudo pacman -R --noconfirm "$pkg" >/dev/null 2>&1
done
# The keyboard rule and kwalletrc are reverted by the theme's journal.
# The wallet itself stays: secrets may have been saved in it since.
# The keyboard rule is reverted by the theme's journal.
return 0
}