From c83b40fe5ef770841456e888d0e8ef347ce4a1d3 Mon Sep 17 00:00:00 2001 From: Padreug Date: Sat, 15 Aug 2026 11:01:11 +0200 Subject: [PATCH] feat(deploy): enable pcscd on upboard (sintra/tejo) for NFC gate MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The access gate (ADR-003, #86) only wired services.pcscd + the pcsc polkit rule into batm3.nix, so the tap-to-enter reader was invisible on upboard machines. Port the same device-agnostic wiring to upboard.nix (HID Global OMNIKEY 5022, 076b:5022) so the gate works on the sintra dev unit — and on tejo — when #86 lands on dev and the nightly upgrade pulls it. Co-Authored-By: Claude Opus 4.8 Claude-Session: https://claude.ai/code/session_018ivBosaWmv8vwFE7ejrdHW --- deploy/nixos/hardware/upboard.nix | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/deploy/nixos/hardware/upboard.nix b/deploy/nixos/hardware/upboard.nix index d213ff7..499179e 100644 --- a/deploy/nixos/hardware/upboard.nix +++ b/deploy/nixos/hardware/upboard.nix @@ -91,6 +91,27 @@ cpuFreqGovernor = "performance"; }; + # PC/SC daemon for the HID Global OMNIKEY 5022 contactless reader + # (076b:5022, a CCID smart-card reader) used for Bolt Card tap-to-enter + # (ADR-003). pcscd binds the CCID driver; the app talks to pcscd's socket + # (via nfc-pcsc) rather than the USB device directly. Device-agnostic — + # same wiring as batm3's Feitian KP382; harmless if no reader is attached, + # pcscd just idles. Shared by every upboard machine (sintra, tejo). + services.pcscd.enable = true; + + # pcscd gates client access via polkit; without a rule the sandboxed + # `bitspire` service user is "Rejected unauthorized PC/SC client". Authorize + # it to talk to the daemon and the card. + security.polkit.extraConfig = '' + polkit.addRule(function(action, subject) { + if ((action.id == "org.debian.pcsc-lite.access_pcsc" || + action.id == "org.debian.pcsc-lite.access_card") && + subject.user == "bitspire") { + return polkit.Result.YES; + } + }); + ''; + # Disable suspend/hibernate for kiosk systemd.targets = { sleep.enable = false;