#!/bin/sh # vestibule-kiosk-launch — the process the kiosk systemd unit execs. # # Reads /etc/vestibule/kiosk.env, then starts the cage compositor with # the configured Gecko browser (LibreWolf or Firefox; native, Flatpak, # or snap) as its only client. dbus-run-session provides the session # bus that both cage children and sandboxed browsers need. # # Installed to /usr/local/bin by provision-kiosk.sh. Edit # /etc/vestibule/kiosk.env to change behavior — never this file. # # kiosk.env keys: # VESTIBULE_HOME_URL page the kiosk opens (default: about:blank) # VESTIBULE_BROWSER librewolf (default) | firefox # VESTIBULE_BROWSER_FLAVOR native (default) | flatpak | snap # VESTIBULE_CAGE_ARGS extra cage flags (default: -d) # # Dispatch is step-down: flavor first (flatpak runs the sandbox app), # then browser name (native and snap flavors share the plain exec). # # POSIX sh — no bashisms. Runs on any minimal Linux base. set -eu ENV_FILE="/etc/vestibule/kiosk.env" if [ -r "${ENV_FILE}" ]; then . "${ENV_FILE}" fi : "${VESTIBULE_HOME_URL:=about:blank}" : "${VESTIBULE_BROWSER:=librewolf}" : "${VESTIBULE_BROWSER_FLAVOR:=native}" # cage flags: "-d" allows VT switching (admin escape hatch — switch away # from the kiosk with Ctrl+Alt+F3 etc. on cage >= 0.1.2). Set to "" on # older cage builds that reject it. : "${VESTIBULE_CAGE_ARGS:=-d}" LW_FLATPAK_APP="io.gitlab.librewolf-community" FF_FLATPAK_APP="org.mozilla.firefox" # Gecko defaults to X11 and cage ships no Xwayland: force native Wayland # or the browser exits with "cannot open display". Applies to every # Gecko flavor — LibreWolf and Firefox alike. MOZ_ENABLE_WAYLAND=1 GDK_BACKEND=wayland XDG_SESSION_TYPE=wayland export MOZ_ENABLE_WAYLAND GDK_BACKEND XDG_SESSION_TYPE CAGE="cage" command -v cage >/dev/null 2>&1 || CAGE="/usr/bin/cage" URL="${VESTIBULE_HOME_URL}" if [ "${VESTIBULE_BROWSER_FLAVOR}" = "flatpak" ]; then FLATPAK_APP="${LW_FLATPAK_APP}" case "${VESTIBULE_BROWSER}" in firefox) FLATPAK_APP="${FF_FLATPAK_APP}" ;; esac # shellcheck disable=SC2086 # VESTIBULE_CAGE_ARGS is intentionally word-split exec dbus-run-session -- "${CAGE}" ${VESTIBULE_CAGE_ARGS} -- \ flatpak run "${FLATPAK_APP}" \ --kiosk -P vestibule-profile -no-remote "${URL}" fi # native and snap flavors both exec the browser by name — the snap # wrapper ships the same CLI. BROWSER_BIN="librewolf" case "${VESTIBULE_BROWSER}" in firefox) BROWSER_BIN="firefox" ;; esac # shellcheck disable=SC2086 # VESTIBULE_CAGE_ARGS is intentionally word-split exec dbus-run-session -- "${CAGE}" ${VESTIBULE_CAGE_ARGS} -- \ "${BROWSER_BIN}" --kiosk -P vestibule-profile -no-remote "${URL}"