fix: give the live session user access to the console VT

Xorg failed to start with:

    (EE) xf86OpenConsole: Cannot open virtual console 1 (Permission denied)

udev leaves console VTs as 620 root:tty — group tty has write-only, so
even a tty-group member can't open /dev/tty1 read+write (display managers
normally get this via logind seat ACLs, which a manually-started X
doesn't have). The session script now chowns the dedicated VT to
liveuser before starting X; the unit already Conflicts with getty@tty1 so
nothing else needs it.
This commit is contained in:
Blake Ridgway
2026-08-21 20:38:25 -05:00
parent 04bcb684b3
commit 7a3a245d36
2 changed files with 21 additions and 5 deletions

View File

@@ -48,10 +48,15 @@ the live session with the installer in it.
`overlays/live/etc/systemd/system/arcline-installer.service` starts
`arcline-installer-session` on boot. Modern Xorg (trixie 21.1.x) refuses to
run as root, so the session script starts Xorg as the dedicated unprivileged
`liveuser` account on vt1, grants root display access (`xhost
+SI:localuser:root`), then runs the installer as root (it needs root for
`deploy-disk.sh`). When the installer exits, X and the session end.
run as root, so the session script:
1. hands the dedicated console VT to `liveuser` (`chown`, since udev leaves
VTs 620 root:tty which isn't readable by the tty group),
2. starts Xorg as the unprivileged `liveuser` on vt1,
3. grants root display access (`xhost +SI:localuser:root`),
4. runs the installer as root (it needs root for `deploy-disk.sh`).
When the installer exits, X and the session end.
## Manual run (for development / on a box without the ISO)

View File

@@ -10,9 +10,20 @@ set -euo pipefail
export DISPLAY=:0
LXUSER=liveuser
VT=1
TTY="/dev/tty$VT"
# udev leaves console VTs as 620 root:tty — group tty has write-only, no read,
# so Xorg's xf86OpenConsole fails with "Cannot open virtual console (Permission
# denied)". This VT is dedicated to the installer (the unit Conflicts with
# getty@tty1), so hand it to liveuser outright.
chown "$LXUSER" "$TTY" 2>/dev/null || true
# clear stale X state from a previous attempt in the same boot
rm -f /tmp/.X0-lock /tmp/.X11-unix/X0 2>/dev/null || true
# 1. start Xorg as the unprivileged user on vt1 (no -allow-root; it's gone)
runuser -u "$LXUSER" -- /usr/bin/Xorg :0 vt1 -nolisten tcp &
runuser -u "$LXUSER" -- /usr/bin/Xorg :0 "vt$VT" -nolisten tcp &
XPID=$!
# 2. wait for the X socket