feat(idle): no double-unlock after an encrypted hibernate resume
hypridle locks hyprlock before every sleep -- right for suspend, but redundant for hibernate: the LUKS passphrase entered at boot already gates the resume, so the user typed a password twice. Add a nomarchy-hibernate- unlock systemd unit (WantedBy hibernate.target, After systemd-hibernate.service => runs post-resume) that dismisses hyprlock, gated on the disk being LUKS- encrypted. Suspend (and the RAM-resume phase of suspend-then-hibernate) keep locking -- they have no passphrase gate; an unencrypted hibernate keeps its lock too. idle.nix gains a pointer comment; roadmap item marked done. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -114,6 +114,26 @@ in
|
||||
services.upower.enable = lib.mkDefault true;
|
||||
networking.networkmanager.enable = lib.mkDefault true;
|
||||
|
||||
# No double-unlock on hibernate. hypridle locks hyprlock before every
|
||||
# sleep (right for suspend), but a hibernate resume is already gated by
|
||||
# the LUKS passphrase entered at boot — so the user would type a password
|
||||
# twice. Once we're back from an *encrypted* hibernate, drop the now-
|
||||
# redundant hyprlock. Ordered After the hibernate service, so it runs
|
||||
# post-resume; pulled in only by hibernate.target (suspend, and the
|
||||
# RAM-resume phase of suspend-then-hibernate, stay locked — they have no
|
||||
# passphrase gate). Gated on LUKS: an unencrypted hibernate keeps its lock.
|
||||
systemd.services.nomarchy-hibernate-unlock =
|
||||
lib.mkIf (builtins.attrNames config.boot.initrd.luks.devices != [ ]) {
|
||||
description = "Dismiss hyprlock after resuming from an encrypted hibernate";
|
||||
after = [ "systemd-hibernate.service" ];
|
||||
wantedBy = [ "hibernate.target" ];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
# `-`: a missing hyprlock (idle disabled, or not locked) isn't a failure.
|
||||
ExecStart = "-${pkgs.procps}/bin/pkill -x hyprlock";
|
||||
};
|
||||
};
|
||||
|
||||
# zsh as the default login shell (the desktop's shell experience —
|
||||
# starship/bat/eza/zoxide — is configured home-side in shell.nix).
|
||||
# programs.zsh.enable wires /etc/zshrc, completion and /etc/shells;
|
||||
|
||||
Reference in New Issue
Block a user