fix: run the live X session as an unprivileged user

The workstation ISO failed to start X with:

    (EE) unrecognized option --allow-root

Debian trixie ships Xorg 21.1.x, which removed --allow-root / -allowRoot
entirely — running the X server as root is no longer supported. The live
session now:

- creates a dedicated unprivileged `liveuser` account (in tty, video,
  input, audio groups) in build-live.sh;
- starts Xorg as `liveuser` on vt1 (no -allow-root flag at all);
- grants root display access (xhost +SI:localuser:root);
- still runs the installer itself as root, since deploy-disk.sh needs
  root. xinit is no longer used (and dropped from the package list).
This commit is contained in:
Blake Ridgway
2026-08-21 20:31:19 -05:00
parent 0ea8b713dd
commit 04bcb684b3
3 changed files with 41 additions and 10 deletions

View File

@@ -1,11 +1,33 @@
#!/usr/bin/env bash
# Arcline OS — live session: start X on vt1 and launch the graphical installer.
# Runs as root in the live session; Xorg needs -allow-root for that.
# Arcline OS — live session: start X as an unprivileged user, then launch the
# graphical installer as root on that display.
#
# Modern Xorg (Debian trixie 21.1.x) refuses to run as root — the
# --allow-root / -allowRoot option was removed. So X runs as the dedicated
# `liveuser` account, root is granted display access, and the installer (which
# needs root to run deploy-disk.sh) connects to it.
set -euo pipefail
export DISPLAY=:0
# clear any stale lock from a previous session in the same live boot
rm -f /tmp/.X0-lock /tmp/.X11-unix/X0
LXUSER=liveuser
exec xinit /usr/local/bin/arcline-installer -- \
/usr/bin/Xorg -allow-root -nolisten tcp -keeptty :0 vt1
# 1. start Xorg as the unprivileged user on vt1 (no -allow-root; it's gone)
runuser -u "$LXUSER" -- /usr/bin/Xorg :0 vt1 -nolisten tcp &
XPID=$!
# 2. wait for the X socket
for _ in $(seq 1 60); do
[[ -S /tmp/.X11-unix/X0 ]] && break
sleep 0.5
done
[[ -S /tmp/.X11-unix/X0 ]] || { echo "error: Xorg did not come up on :0" >&2; kill "$XPID" 2>/dev/null || true; exit 1; }
# 3. let root open windows on this display
runuser -u "$LXUSER" -- xhost +SI:localuser:root >/dev/null 2>&1 || true
# 4. run the installer as root (deploy-disk.sh needs root)
runuser -u root -- env DISPLAY=:0 /usr/local/bin/arcline-installer
rc=$?
kill "$XPID" 2>/dev/null || true
exit "$rc"