74 lines
2.6 KiB
Bash
Executable File
74 lines
2.6 KiB
Bash
Executable File
#!/bin/sh
|
|
# vestibule-kiosk-launch — the process the kiosk systemd unit execs.
|
|
#
|
|
# Reads /etc/vestibule/kiosk.env, then starts the cage compositor with
|
|
# the configured Gecko browser (LibreWolf or Firefox; native, Flatpak,
|
|
# or snap) as its only client. dbus-run-session provides the session
|
|
# bus that both cage children and sandboxed browsers need.
|
|
#
|
|
# Installed to /usr/local/bin by provision-kiosk.sh. Edit
|
|
# /etc/vestibule/kiosk.env to change behavior — never this file.
|
|
#
|
|
# kiosk.env keys:
|
|
# VESTIBULE_HOME_URL page the kiosk opens (default: about:blank)
|
|
# VESTIBULE_BROWSER librewolf (default) | firefox
|
|
# VESTIBULE_BROWSER_FLAVOR native (default) | flatpak | snap
|
|
# VESTIBULE_CAGE_ARGS extra cage flags (default: -d)
|
|
#
|
|
# Dispatch is step-down: flavor first (flatpak runs the sandbox app),
|
|
# then browser name (native and snap flavors share the plain exec).
|
|
#
|
|
# POSIX sh — no bashisms. Runs on any minimal Linux base.
|
|
|
|
set -eu
|
|
|
|
ENV_FILE="/etc/vestibule/kiosk.env"
|
|
if [ -r "${ENV_FILE}" ]; then
|
|
. "${ENV_FILE}"
|
|
fi
|
|
|
|
: "${VESTIBULE_HOME_URL:=about:blank}"
|
|
: "${VESTIBULE_BROWSER:=librewolf}"
|
|
: "${VESTIBULE_BROWSER_FLAVOR:=native}"
|
|
# cage flags: "-d" allows VT switching (admin escape hatch — switch away
|
|
# from the kiosk with Ctrl+Alt+F3 etc. on cage >= 0.1.2). Set to "" on
|
|
# older cage builds that reject it.
|
|
: "${VESTIBULE_CAGE_ARGS:=-d}"
|
|
|
|
LW_FLATPAK_APP="io.gitlab.librewolf-community"
|
|
FF_FLATPAK_APP="org.mozilla.firefox"
|
|
|
|
# Gecko defaults to X11 and cage ships no Xwayland: force native Wayland
|
|
# or the browser exits with "cannot open display". Applies to every
|
|
# Gecko flavor — LibreWolf and Firefox alike.
|
|
MOZ_ENABLE_WAYLAND=1
|
|
GDK_BACKEND=wayland
|
|
XDG_SESSION_TYPE=wayland
|
|
export MOZ_ENABLE_WAYLAND GDK_BACKEND XDG_SESSION_TYPE
|
|
|
|
CAGE="cage"
|
|
command -v cage >/dev/null 2>&1 || CAGE="/usr/bin/cage"
|
|
|
|
URL="${VESTIBULE_HOME_URL}"
|
|
|
|
if [ "${VESTIBULE_BROWSER_FLAVOR}" = "flatpak" ]; then
|
|
FLATPAK_APP="${LW_FLATPAK_APP}"
|
|
case "${VESTIBULE_BROWSER}" in
|
|
firefox) FLATPAK_APP="${FF_FLATPAK_APP}" ;;
|
|
esac
|
|
# shellcheck disable=SC2086 # VESTIBULE_CAGE_ARGS is intentionally word-split
|
|
exec dbus-run-session -- "${CAGE}" ${VESTIBULE_CAGE_ARGS} -- \
|
|
flatpak run "${FLATPAK_APP}" \
|
|
--kiosk -P vestibule-profile -no-remote "${URL}"
|
|
fi
|
|
|
|
# native and snap flavors both exec the browser by name — the snap
|
|
# wrapper ships the same CLI.
|
|
BROWSER_BIN="librewolf"
|
|
case "${VESTIBULE_BROWSER}" in
|
|
firefox) BROWSER_BIN="firefox" ;;
|
|
esac
|
|
# shellcheck disable=SC2086 # VESTIBULE_CAGE_ARGS is intentionally word-split
|
|
exec dbus-run-session -- "${CAGE}" ${VESTIBULE_CAGE_ARGS} -- \
|
|
"${BROWSER_BIN}" --kiosk -P vestibule-profile -no-remote "${URL}"
|