aboutsummaryrefslogtreecommitdiffhomepage
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2025-12-08 22:29:41 +0900
committerOphestra <cat@gensokyo.uk>2025-12-08 22:29:41 +0900
commitd5fb179012e36436a81761502948c91d44d21cc3 (patch)
tree512f44f6bc8519aa4e4a4853c0419869ebaf2570
parent462863e2908bf14d36f726a06bf22e9e1aceb7b5 (diff)
cmd/hakurei: exec instead of fork/exec from shell
There is no reason to keep the shell process around. Signed-off-by: Ophestra <cat@gensokyo.uk>
-rw-r--r--cmd/hakurei/command.go2
-rw-r--r--nixos.nix2
-rw-r--r--test/interactive/hakurei.nix2
-rw-r--r--test/test.py1
4 files changed, 4 insertions, 3 deletions
diff --git a/cmd/hakurei/command.go b/cmd/hakurei/command.go
index 8f20c8ed..ca685790 100644
--- a/cmd/hakurei/command.go
+++ b/cmd/hakurei/command.go
@@ -191,7 +191,7 @@ func buildCommand(ctx context.Context, msg message.Msg, early *earlyHardeningErr
if flagPulse {
config.Container.Filesystem = append(config.Container.Filesystem, hst.FilesystemConfigJSON{FilesystemConfig: &hst.FSDaemon{
Target: fhs.AbsRunUser.Append(strconv.Itoa(container.OverflowUid(msg)), "pulse/native"),
- Exec: shell, Args: []string{"-lc", "pipewire-pulse"},
+ Exec: shell, Args: []string{"-lc", "exec pipewire-pulse"},
}})
}
diff --git a/nixos.nix b/nixos.nix
index 2f238eeb..2b2b42f7 100644
--- a/nixos.nix
+++ b/nixos.nix
@@ -202,7 +202,7 @@ in
path = cfg.shell;
args = [
"-lc"
- "pipewire-pulse"
+ "exec pipewire-pulse"
];
}
++ [
diff --git a/test/interactive/hakurei.nix b/test/interactive/hakurei.nix
index 96f014ce..eb24c7e7 100644
--- a/test/interactive/hakurei.nix
+++ b/test/interactive/hakurei.nix
@@ -37,7 +37,7 @@
path = "/bin/sh";
args = [
"-lc"
- "sleep 1 && false"
+ "sleep 1 && exec false"
];
}
];
diff --git a/test/test.py b/test/test.py
index d1edca4c..9b06a8f2 100644
--- a/test/test.py
+++ b/test/test.py
@@ -233,6 +233,7 @@ collect_state_ui("pipewire_wayland")
machine.send_chars("exit\n")
machine.wait_until_fails("pgrep foot", timeout=5)
# Test PipeWire SecurityContext:
+machine.succeed("sudo -u alice -i XDG_RUNTIME_DIR=/run/user/1000 hakurei -v run --pulse pactl info")
machine.fail("sudo -u alice -i XDG_RUNTIME_DIR=/run/user/1000 hakurei -v run --pulse pactl set-sink-mute @DEFAULT_SINK@ toggle")
# Test XWayland (foot does not support X):