Platforms
Linux is the only platform touchcue works on. CI builds and tests touchcue on Windows and macOS too, but there it has no sources or output backends: run, list-devices, trace and gpg print not supported on this platform yet and exit with status 2.
Linux
- Runs as a user process, in the foreground or as a systemd user service. See Getting started.
- Detects FIDO keys by reading their
/dev/hidraw*nodes read-only, alongside browsers and ssh, without taking reports from them. It needs read access to those nodes. touchcue ships no udev rules: the access must come from the system's existing rules, which on most systemd distributions grant the logged-in user access to FIDO security keys through theuaccesstag.touchcue checkshows whether each key is readable. - Names the requesting application by finding the processes that hold the device open in
/proc, then their application through their cgroup unit or, failing that, their executable and its desktop entry. OpenPGP requests are attributed to the newest client of gpg-agent. - Shows popups through Wayland layer-shell or X11, including XWayland, and notifications through the session D-Bus.
An optional privileged helper, touchcue-helper, is planned for exact attribution of root callers, PIV and OATH, and Ledger. The binary exists but does nothing yet.
Planned sources: PIV, OATH, YubiKey HMAC/OTP, fprintd, Trezor and Ledger.
Windows
Planned.
- FIDO HID access is expected to need a SYSTEM service.
- Other details are under investigation.
macOS
Planned.
- A signed
.appwith a LaunchAgent is planned. - Input Monitoring permission may be needed. Under investigation.