Skip to content

Linux AppImage helper: pkexec front-end + uaccess-first (drop mandatory input group) #173

Description

@jonocodes

Follow-up to #171 (Linux AppImage packaging, phase 0 of #168).

The one-time install helper works and is verified, but the root step can be friendlier and smaller:

  • pkexec front-end. Desktop users should be able to run
    pkexec ./deckd-install-system-integration.sh ./deckd-<version>-x86_64.AppImage
    and get the native polkit password dialog instead of a terminal sudo. The helper must resolve the target user from PKEXEC_UID as well as SUDO_USER, and print the rerun/uninstall command matching how it was invoked. Keep sudo documented for headless/SSH.
  • uaccess-first. The shipped udev rule already has TAG+="uaccess", so on logind desktops the active seat user gets an ACL on /dev/uinput — the input group add (and its "log out and back in") is unnecessary for the autostart-at-login case. Make the group opt-in (--add-group) for linger/headless setups and reword the install output.
  • Maybe: when /dev/uinput can't be opened, surface a one-time-setup notice (client banner or log line) with the exact command — an on-demand prompt like balenaEtcher, as a notice rather than a blocker.

Verification: re-run the sandboxed install→uninstall lifecycle (pre-existing group/extension/icon preserved) plus the live-session focus/injection checks; confirm the pkexec path on a real desktop.

Activity

  1. added
    enhancementNew feature or request
    human-verification-requiredCode is complete; a human must verify on real hardware / a live session before closing
    on Sep 30, 2026
  2. added a commit that references this issue on Sep 30, 2026
  3. jonocodes commented on Sep 30, 2026

    @jonocodes
    OwnerAuthor

    Merged in #175 (e0dc69e). Keeping this open for the one human step.

    Human verification (non-Nix distro):

    • pkexec ./deckd-install-system-integration.sh ./deckd-<version>-x86_64.AppImage pops the polkit password dialog and completes the install.
    • No relogin is needed afterwards for injection (uaccess ACL on /dev/uinput).
    • The printed --uninstall command (same front-end) removes only what was installed.

    NixOS testers: pkexec resets PATH with no system profile — use sudo, or pkexec /run/current-system/sw/bin/bash ./deckd-install-system-integration.sh ....

    Already verified: sandboxed install/uninstall across non-member ± --add-group, pre-existing member, pkexec vs sudo resolution, the --assets exit-code fix, pytest 778, pyright clean, bundled helper diffed against source.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requesthuman-verification-requiredCode is complete; a human must verify on real hardware / a live session before closing

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions