Bins live in /usr/local, so a later useradd no longer gets ~/.local/bin copies. systemctl --global enable the bakery --user units (bake writes /etc/systemd/user/*.wants/, and post-install + live-setup run the same enable) so first login starts breadd, breadbox-sync, breadclipd, breadcrumbs, and breadmill. Stock useradd -m copies skel (Hyprland + bakery state). Rollback is still grub-btrfs.
62 lines
2.9 KiB
Bash
62 lines
2.9 KiB
Bash
#!/bin/bash
|
|
# Create the unprivileged BOS live user and its Hyprland session.
|
|
#
|
|
# Hyprland refuses to run as root (superuser-privileges check), so the live
|
|
# session must run as a normal user. Calamares — which does need root — is
|
|
# launched onto the user's Wayland socket via passwordless sudo (see
|
|
# bos-launch-calamares). Runs once at boot, before the tty1 autologin getty.
|
|
set -e
|
|
|
|
# Bakery user units live in /usr/lib/systemd/user. --global enable writes
|
|
# /etc/systemd/user/*.wants/ so liveuser (and any later account) starts
|
|
# them on first login. Idempotent; bins are already in /usr/local.
|
|
if [[ -x /usr/local/bin/bos-enable-bakery-user-units ]]; then
|
|
/usr/local/bin/bos-enable-bakery-user-units \
|
|
|| echo "WARN: enabling bakery user units globally failed"
|
|
fi
|
|
|
|
# useradd -m copies /etc/skel, so the live user gets the real BOS desktop
|
|
# (hypr + bread config + bakery state) — proper live-media functionality,
|
|
# not an installer kiosk. Binaries are /usr/local, not skel.
|
|
if ! id liveuser &>/dev/null; then
|
|
useradd -m -s /usr/bin/zsh liveuser
|
|
for g in wheel video input audio storage power; do
|
|
getent group "$g" >/dev/null 2>&1 && gpasswd -a liveuser "$g" >/dev/null || true
|
|
done
|
|
passwd -d liveuser >/dev/null
|
|
fi
|
|
|
|
# Layer the installer onto the live desktop: auto-launch it, and bind
|
|
# Super+Shift+I to relaunch it after it's been closed. Appended (in Lua) to
|
|
# the skel hyprland.lua native config so the full desktop stays intact.
|
|
# NOTE: plain SUPER+I is float-toggle in the skel config — don't reuse it
|
|
# here, it was tried once and silently double-bound both actions.
|
|
HYPR=/home/liveuser/.config/hypr/hyprland.lua
|
|
install -d -m 0755 -o liveuser -g liveuser /home/liveuser/.config/hypr
|
|
if ! grep -q bos-launch-calamares "$HYPR" 2>/dev/null; then
|
|
cat >>"$HYPR" <<'EOF'
|
|
|
|
-- --- live-media installer (added by bos-live-setup; absent on installed system) ---
|
|
hl.bind("SUPER + SHIFT + I", hl.dsp.exec_cmd("bos-launch-calamares"))
|
|
hl.on("hyprland.start", function() hl.dispatch(hl.dsp.exec_cmd("bos-launch-calamares")) end)
|
|
EOF
|
|
fi
|
|
|
|
# Start Hyprland on tty1 login; capture output and fall back to a shell so a
|
|
# failed compositor start is visible rather than a blank looping cursor.
|
|
# liveuser's shell is zsh (see useradd above), which never sources
|
|
# .bash_profile — this must be .zprofile (zsh's login-shell hook) or it never
|
|
# runs at all and the live session boots to a bare console.
|
|
cat >/home/liveuser/.zprofile <<'EOF'
|
|
if [[ "$(tty)" == /dev/tty1 ]] && [[ -z "$WAYLAND_DISPLAY" ]]; then
|
|
export WLR_RENDERER_ALLOW_SOFTWARE=1
|
|
export WLR_NO_HARDWARE_CURSORS=1
|
|
# Log to a user-writable path (/var/log is root-only; redirecting there
|
|
# would fail and silently keep the compositor from ever launching).
|
|
start-hyprland &>/tmp/hyprland-live.log
|
|
echo "Hyprland exited (rc=$?). Log: /tmp/hyprland-live.log"
|
|
exec zsh -i
|
|
fi
|
|
EOF
|
|
|
|
chown -R liveuser:liveuser /home/liveuser
|