Merge nucleic/lucid-lunar-wren-wxyw into dev
This commit is contained in:
@@ -0,0 +1,14 @@
|
||||
Package: naros-desktop-config
|
||||
Version: @VERSION@
|
||||
Architecture: all
|
||||
Maintainer: Nucleic <[email protected]>
|
||||
Section: misc
|
||||
Priority: optional
|
||||
Depends: gdm3, dconf-cli, dbus, at-spi2-core, nash
|
||||
Description: narOS VM desktop configuration (NAROS.md §7.4 N5; LINUX_VM_SEMANTIC_AGENT.md)
|
||||
The Nucleic desktop policy the old Ubuntu provisioner applied by hand, packaged:
|
||||
the `agent` auto-login account (uid 501, nash shell, passwordless sudo), GDM
|
||||
Wayland auto-login, system dconf defaults (AT-SPI on, integer scale = 1, no
|
||||
idle/lock/blank, GNOME welcome suppressed, the Mutter geometry-helper extension
|
||||
enabled), the geometry-helper GNOME Shell extension itself, QT_ACCESSIBILITY, and
|
||||
boot-to-graphical. Installing it turns the naros base into the computer-use guest.
|
||||
@@ -0,0 +1,32 @@
|
||||
# System-wide dconf defaults for the naros-vm desktop guest (NAROS.md §7.4 N5). Applied to the
|
||||
# auto-login agent session without a per-user seed. Ported from the old Ubuntu provisioner's
|
||||
# dconf block (docs/LINUX_VM_SEMANTIC_AGENT.md Phase 2). `dconf update` (postinst) compiles this.
|
||||
[org/gnome/desktop/interface]
|
||||
# Turn the AT-SPI bridge on for GTK/GNOME apps so the semantic agent sees their trees — the
|
||||
# whole point of the desktop flavor.
|
||||
toolkit-accessibility=true
|
||||
# Integer display scale = 1 (no fractional scaling): the invariant that makes the compositor's
|
||||
# window coordinates equal the virtio-gpu scanout pixels the host captures 1:1, so ax_dump
|
||||
# frames are directly clickable.
|
||||
scaling-factor=uint32 1
|
||||
|
||||
[org/gnome/mutter]
|
||||
# Do NOT enable fractional scaling — keep logical == physical pixels.
|
||||
experimental-features=@as []
|
||||
|
||||
[org/gnome/desktop/session]
|
||||
idle-delay=uint32 0
|
||||
|
||||
[org/gnome/desktop/screensaver]
|
||||
lock-enabled=false
|
||||
idle-activation-enabled=false
|
||||
|
||||
[org/gnome/settings-daemon/plugins/power]
|
||||
sleep-inactive-ac-type='nothing'
|
||||
sleep-inactive-battery-type='nothing'
|
||||
|
||||
[org/gnome/shell]
|
||||
welcome-dialog-last-shown-version='99.0'
|
||||
disable-user-extensions=false
|
||||
# The Nucleic Mutter geometry helper (focused-window global origin for the AT-SPI agent).
|
||||
enabled-extensions=['[email protected]']
|
||||
@@ -0,0 +1,2 @@
|
||||
user-db:user
|
||||
system-db:local
|
||||
@@ -0,0 +1,4 @@
|
||||
# Qt apps read this to enable their AT-SPI bridge (GTK does so automatically once the a11y bus
|
||||
# is up). systemd's user session sources /etc/environment.d/*.conf into the graphical session.
|
||||
# Chromium/Electron still need a per-launch --force-renderer-accessibility (the agent handles it).
|
||||
QT_ACCESSIBILITY=1
|
||||
@@ -0,0 +1,3 @@
|
||||
# narOS agent user (NAROS.md §6.1): frictionless escalation for `apt install` etc.,
|
||||
# non-interactive. The disposable, NAT-isolated VM is the isolation boundary.
|
||||
agent ALL=(ALL) NOPASSWD:ALL
|
||||
@@ -0,0 +1,42 @@
|
||||
#!/bin/sh
|
||||
# Realize the naros-vm desktop policy (NAROS.md §7.4 N5). Runs at image-build configure time in
|
||||
# the mmdebstrap chroot (no running systemd) — every step is offline-safe.
|
||||
set -e
|
||||
[ "$1" = "configure" ] || exit 0
|
||||
|
||||
# 1. The narOS `agent` user GDM auto-logs into. uid 501 is in lockstep with the sandbox/agent
|
||||
# tiers (the uid ContainerEngine execs as); login shell is the contract nash path.
|
||||
if ! id -u agent >/dev/null 2>&1; then
|
||||
useradd --uid 501 --user-group --create-home --home-dir /home/agent \
|
||||
--shell /usr/local/bin/nash agent
|
||||
fi
|
||||
for g in video input render sudo; do
|
||||
getent group "$g" >/dev/null 2>&1 && usermod -aG "$g" agent || true
|
||||
done
|
||||
passwd -l agent >/dev/null 2>&1 || true # auto-login only, no password
|
||||
|
||||
# 2. sudoers drop-in must be 0440 (git can't track that mode).
|
||||
chmod 0440 /etc/sudoers.d/naros-agent 2>/dev/null || true
|
||||
|
||||
# 3. GDM auto-login into the agent's Wayland session, so the host surface sees a live screen.
|
||||
# (Debian gdm3 reads /etc/gdm3/daemon.conf; we own the desktop policy, so write it whole.)
|
||||
mkdir -p /etc/gdm3
|
||||
cat > /etc/gdm3/daemon.conf <<'GDM'
|
||||
[daemon]
|
||||
WaylandEnable=true
|
||||
AutomaticLoginEnable=true
|
||||
AutomaticLogin=agent
|
||||
GDM
|
||||
|
||||
# 4. Compile the system dconf defaults (AT-SPI on, scale=1, no idle/lock, geometry ext enabled).
|
||||
dconf update 2>/dev/null || true
|
||||
|
||||
# 5. Boot to the graphical session.
|
||||
systemctl set-default graphical.target >/dev/null 2>&1 || true
|
||||
|
||||
# 6. Skip GNOME's first-run tour so the first host screenshot is a usable desktop.
|
||||
mkdir -p /home/agent/.config
|
||||
echo yes > /home/agent/.config/gnome-initial-setup-done
|
||||
chown -R agent:agent /home/agent/.config 2>/dev/null || true
|
||||
|
||||
exit 0
|
||||
@@ -0,0 +1,11 @@
|
||||
# Stage the Mutter geometry-helper GNOME Shell extension (guest/mutter-geometry-helper) into
|
||||
# the system extensions dir. It exposes the focused window's true global origin over a private
|
||||
# D-Bus name for the AT-SPI agent (AT-SPI loses the window origin on Wayland) — enabled via the
|
||||
# dconf default in files/etc/dconf/db/local.d/00-nucleic. Arch-independent (JS + metadata).
|
||||
stage() {
|
||||
local dest="$1"
|
||||
local ext="$dest/usr/share/gnome-shell/extensions/[email protected]"
|
||||
local src="$OS_DIR/../guest/mutter-geometry-helper"
|
||||
install -D -m 0644 "$src/metadata.json" "$ext/metadata.json"
|
||||
install -D -m 0644 "$src/extension.js" "$ext/extension.js"
|
||||
}
|
||||
@@ -0,0 +1,15 @@
|
||||
Package: naros-tier-vm-desktop
|
||||
Version: @VERSION@
|
||||
Architecture: all
|
||||
Maintainer: Nucleic <[email protected]>
|
||||
Section: metapackages
|
||||
Priority: optional
|
||||
Depends: naros-tier-vm, naros-desktop-config, nucleic-a11y-agent, gnome-session, gnome-shell, gdm3, at-spi2-core, xwayland, firefox-esr
|
||||
Description: narOS VM guest tier — desktop flavor (GNOME 50, NAROS.md §7.4, milestone N5)
|
||||
The full computer-use / semantic-agent surface, layered on the headless VM tier
|
||||
(naros-tier-vm). Ties together the GNOME 50 / Mutter Wayland session (baked from
|
||||
the pinned Debian forky snapshot), GDM auto-login, the AT-SPI accessibility bus,
|
||||
the Rust semantic agent (nucleic-a11y-agent), and the Nucleic desktop config
|
||||
(naros-desktop-config: agent auto-login user, dconf defaults, Mutter geometry
|
||||
helper, Firefox policy). Built into the naros-vm-desktop rootfs, not apt-installed
|
||||
at firstboot.
|
||||
@@ -0,0 +1,13 @@
|
||||
Package: nucleic-a11y-agent
|
||||
Version: @VERSION@
|
||||
Architecture: @ARCH@
|
||||
Maintainer: Nucleic <[email protected]>
|
||||
Section: admin
|
||||
Priority: optional
|
||||
Depends: at-spi2-core
|
||||
Description: Nucleic Linux guest AT-SPI semantic agent (NAROS.md §7.4 N5; LINUX_VM_SEMANTIC_AGENT.md)
|
||||
The Rust (zbus/tokio) accessibility agent — the ax_* semantic control plane over
|
||||
AF_VSOCK port 2036. A systemd USER service inside the graphical session so it can
|
||||
reach that session's AT-SPI a11y bus. Baked into the naros-vm desktop flavor
|
||||
(pulled by naros-tier-vm-desktop); complements the static-C nucleic-linux-agent
|
||||
(exec, port 2035). Absent → the host falls back to screenshot + pixel actions.
|
||||
@@ -0,0 +1,21 @@
|
||||
# Stage the prebuilt Rust AT-SPI semantic agent + its systemd USER unit, with a static
|
||||
# global-enable symlink so it starts in every graphical session (no `systemctl --global
|
||||
# enable` needed inside the mmdebstrap chroot). Prefer the CI-built dist/bin binary; fall
|
||||
# back to the committed guest build (arm64) — the same artifact the pre-narOS base build bakes.
|
||||
stage() {
|
||||
local dest="$1" arch="$2"
|
||||
local bin="$OS_DIR/dist/bin/nucleic-a11y-agent-$arch"
|
||||
if [ ! -x "$bin" ] && [ "$arch" = arm64 ]; then
|
||||
bin="$OS_DIR/../guest/nucleic-a11y-agent/build/nucleic-a11y-agent"
|
||||
fi
|
||||
local unit="$OS_DIR/../guest/nucleic-a11y-agent/systemd/nucleic-a11y-agent.service"
|
||||
if [ ! -x "$bin" ]; then
|
||||
echo "prebuilt binary missing: dist/bin/nucleic-a11y-agent-$arch" > "$dest/.skip-reason"
|
||||
return 1
|
||||
fi
|
||||
install -D -m 0755 "$bin" "$dest/usr/local/bin/nucleic-a11y-agent"
|
||||
install -D -m 0644 "$unit" "$dest/usr/lib/systemd/user/nucleic-a11y-agent.service"
|
||||
install -d "$dest/etc/systemd/user/graphical-session.target.wants"
|
||||
ln -sf /usr/lib/systemd/user/nucleic-a11y-agent.service \
|
||||
"$dest/etc/systemd/user/graphical-session.target.wants/nucleic-a11y-agent.service"
|
||||
}
|
||||
Reference in New Issue
Block a user