[Unit] Description=Select the fingerprint reader for the laptop lid state Wants=dbus.service After=dbus.service [Service] Type=simple ExecStartPre=/usr/local/bin/fingerprint-switch prepare ExecStart=/usr/local/bin/fingerprint-switch watch-lid Restart=on-failure RestartSec=3 RuntimeDirectory=fingerprint-switch RuntimeDirectoryMode=0755 RuntimeDirectoryPreserve=yes UMask=0077 # The watcher only reads lid/USB state and writes fprintd's environment file. # Root identity allows its system-bus request to restart fprintd. User=root Group=root NoNewPrivileges=true CapabilityBoundingSet= ProtectSystem=strict ProtectHome=true ReadWritePaths=/run/fingerprint-switch PrivateTmp=true PrivateDevices=true ProtectKernelTunables=true ProtectKernelModules=true ProtectKernelLogs=true ProtectControlGroups=true ProtectClock=true RestrictAddressFamilies=AF_UNIX RestrictRealtime=true RestrictSUIDSGID=true LockPersonality=true MemoryDenyWriteExecute=true SystemCallFilter=@system-service [Install] WantedBy=multi-user.target