The official package in place of lemurs-git, and /etc/lemurs/config.toml in lemurs 0.4's structure. It offers only the session scripts that modules place in /etc/lemurs/wms and /etc/lemurs/wayland, never a package's bare desktop entry, which skips the session's start. The service is enabled and never started, stopped or restarted by a push. The tools are the seat's sessions, the default session (lemurs's cache, through sudo -n) and logins from the journal and lemurs's own log. The package swap from lemurs-git is a one-off step for the operator, listed in the README.
70 lines
2.6 KiB
Go
70 lines
2.6 KiB
Go
// lemurs's tools (novox/hq ADR 0208, research 026/05): node-login-manager's verb `sessions`, and the
|
|
// module's own `default_session` and `logins`.
|
|
//
|
|
// None of them needs the graphical session: they read the login manager's configuration, its session
|
|
// directories, its cache and the journal. Changing the default session writes the login manager's
|
|
// cache, which is root's, through `sudo -n` as the packet filter's tools escalate (to-be 38 WP4).
|
|
package main
|
|
|
|
import (
|
|
"context"
|
|
"fmt"
|
|
"os"
|
|
"time"
|
|
|
|
stdio "git.novox.be/novox/mesh-sdk/go"
|
|
|
|
"lemurs/internal/desktop"
|
|
)
|
|
|
|
func main() {
|
|
l := lemurs{d: desktop.Machine(), config: "/etc/lemurs/config.toml", log: "/var/log/lemurs.log", uid: os.Getuid()}
|
|
if err := stdio.Serve("", tools(l)); err != nil {
|
|
fmt.Fprintln(os.Stderr, err)
|
|
os.Exit(1)
|
|
}
|
|
}
|
|
|
|
func call(run func(ctx context.Context, a desktop.Args) (any, error)) func(map[string]any) (any, error) {
|
|
return func(args map[string]any) (any, error) {
|
|
ctx, cancel := context.WithTimeout(context.Background(), 25*time.Second)
|
|
defer cancel()
|
|
return run(ctx, desktop.Args(args))
|
|
}
|
|
}
|
|
|
|
func tools(l lemurs) []stdio.Tool {
|
|
return []stdio.Tool{
|
|
{
|
|
Name: "node-login-manager.sessions",
|
|
Description: "The sessions the login screen offers on this machine — each with its name, X11 or Wayland, " +
|
|
"the file it runs and whether that file is executable (lemurs skips one that is not) — and the " +
|
|
"session and account it starts with by default (its cache).",
|
|
Input: desktop.Schema(map[string]any{}),
|
|
Run: call(l.sessions),
|
|
},
|
|
{
|
|
Name: "lemurs_default_session",
|
|
Description: "The session the login screen preselects. With session (one of the names sessions lists), " +
|
|
"make it the default: written into lemurs's cache, which lemurs reads when it starts, so it shows at " +
|
|
"the next start of the login screen (a reboot, or lemurs restarted). Escalates with sudo -n.",
|
|
Input: desktop.Schema(map[string]any{
|
|
"session": desktop.Str("the session to preselect (optional)"),
|
|
"account": desktop.Str("the account to preselect with it (optional; the cached one)"),
|
|
}),
|
|
Run: call(l.defaultSession),
|
|
},
|
|
{
|
|
Name: "lemurs_logins",
|
|
Description: "Who logged in through the login screen and when, newest last: sessions opened and closed " +
|
|
"and failed passwords, from the journal, and the sessions lemurs started (which entry, from its own " +
|
|
"log since it last started).",
|
|
Input: desktop.Schema(map[string]any{
|
|
"since": desktop.Str("how far back, as journalctl reads it (default -7d)"),
|
|
"limit": desktop.Int("at most this many events (default 50, at most 500)"),
|
|
}),
|
|
Run: call(l.logins),
|
|
},
|
|
}
|
|
}
|