Honor bread.command.lock.unlock via loginctl unlock-session
All checks were successful
Build and publish package / package (push) Successful in 3m15s
All checks were successful
Build and publish package / package (push) Successful in 3m15s
Subscribe the same locker and breadlock listen handlers. Already unlocked is bread.lock.unlock.done; otherwise run loginctl unlock-session and emit done / failed. Do not call compositor unlock() — PAM stays the compositor path (fail-secure). Document in EVENTS.md and README; drop the "Not implemented: unlock" paragraph. pin/blur stay unimplemented.
This commit is contained in:
parent
495fe1aaad
commit
d49df0b5fa
4 changed files with 135 additions and 39 deletions
24
README.md
24
README.md
|
|
@ -13,13 +13,15 @@ Both use [`bread-theme`](https://git.breadway.dev/Breadway/bread-ecosystem) for
|
|||
|
||||
`breadlock` works the same with or without `breadd`. When `breadd` is
|
||||
running, it publishes `bread.lock.locked` / `bread.lock.unlocked` and
|
||||
honors `bread.command.lock.lock` (emits `bread.lock.lock.done` /
|
||||
`.failed`). Run `breadlock listen` so the command works while unlocked;
|
||||
the locker also subscribes while the session is locked. Super+L remains
|
||||
`loginctl lock-session` (hypridle then runs `breadlock`) — that is the
|
||||
session-level equivalent, not a bus command. See [EVENTS.md](EVENTS.md).
|
||||
`breadgreet` is not on the bus. There is no `bakery.toml` (PAM / pacman
|
||||
exception).
|
||||
honors `bread.command.lock.lock` / `bread.command.lock.unlock` (emits
|
||||
`bread.lock.lock.done` / `.failed` and `bread.lock.unlock.done` /
|
||||
`.failed`). Run `breadlock listen` so both commands work while
|
||||
unlocked; the locker also subscribes while the session is locked.
|
||||
Unlock is `loginctl unlock-session` at the session level — not a
|
||||
passwordless compositor `unlock()`. Super+L remains
|
||||
`loginctl lock-session` (hypridle then runs `breadlock`). See
|
||||
[EVENTS.md](EVENTS.md). `breadgreet` is not on the bus. There is no
|
||||
`bakery.toml` (PAM / pacman exception).
|
||||
|
||||
## Architecture
|
||||
|
||||
|
|
@ -82,9 +84,11 @@ lock_cmd = breadlock
|
|||
```
|
||||
|
||||
`breadlock listen` is the unlocked-path subscriber for
|
||||
`bread.command.lock.lock`. It is not started by hypridle; add it to
|
||||
session startup (`exec-once = breadlock listen`) if a Lua workflow
|
||||
should be able to lock the session while it is unlocked.
|
||||
`bread.command.lock.lock` and `bread.command.lock.unlock`. It is not
|
||||
started by hypridle; add it to session startup
|
||||
(`exec-once = breadlock listen`) if a Lua workflow should be able to
|
||||
lock or unlock the session while it is unlocked. Session-level unlock
|
||||
is `loginctl unlock-session` (the bus verb runs that).
|
||||
|
||||
## Verification (why this is safe to test without a lockout risk)
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue