feat(deploy): enable pcscd on upboard (sintra/tejo) for NFC gate
The access gate (ADR-003, #86) only wired services.pcscd + the pcsc polkit rule into batm3.nix, so the tap-to-enter reader was invisible on upboard machines. Port the same device-agnostic wiring to upboard.nix (HID Global OMNIKEY 5022, 076b:5022) so the gate works on the sintra dev unit — and on tejo — when #86 lands on dev and the nightly upgrade pulls it. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018ivBosaWmv8vwFE7ejrdHW
This commit is contained in:
parent
6676c26761
commit
c83b40fe5e
1 changed files with 21 additions and 0 deletions
|
|
@ -91,6 +91,27 @@
|
||||||
cpuFreqGovernor = "performance";
|
cpuFreqGovernor = "performance";
|
||||||
};
|
};
|
||||||
|
|
||||||
|
# PC/SC daemon for the HID Global OMNIKEY 5022 contactless reader
|
||||||
|
# (076b:5022, a CCID smart-card reader) used for Bolt Card tap-to-enter
|
||||||
|
# (ADR-003). pcscd binds the CCID driver; the app talks to pcscd's socket
|
||||||
|
# (via nfc-pcsc) rather than the USB device directly. Device-agnostic —
|
||||||
|
# same wiring as batm3's Feitian KP382; harmless if no reader is attached,
|
||||||
|
# pcscd just idles. Shared by every upboard machine (sintra, tejo).
|
||||||
|
services.pcscd.enable = true;
|
||||||
|
|
||||||
|
# pcscd gates client access via polkit; without a rule the sandboxed
|
||||||
|
# `bitspire` service user is "Rejected unauthorized PC/SC client". Authorize
|
||||||
|
# it to talk to the daemon and the card.
|
||||||
|
security.polkit.extraConfig = ''
|
||||||
|
polkit.addRule(function(action, subject) {
|
||||||
|
if ((action.id == "org.debian.pcsc-lite.access_pcsc" ||
|
||||||
|
action.id == "org.debian.pcsc-lite.access_card") &&
|
||||||
|
subject.user == "bitspire") {
|
||||||
|
return polkit.Result.YES;
|
||||||
|
}
|
||||||
|
});
|
||||||
|
'';
|
||||||
|
|
||||||
# Disable suspend/hibernate for kiosk
|
# Disable suspend/hibernate for kiosk
|
||||||
systemd.targets = {
|
systemd.targets = {
|
||||||
sleep.enable = false;
|
sleep.enable = false;
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue